2026 CVE Vulnerabilities

56,405 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-21906HIGH8.7An Improper Handling of Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks J...
CVE-2026-21905HIGH8.7A Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the SIP application layer gateway (ALG) of Jun...
CVE-2026-21903HIGH7.1A Stack-based Buffer Overflow vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS allows a ...
CVE-2026-0203HIGH7.1An Improper Handling of Exceptional Conditions vulnerability in packet processing of Juniper Networks Junos OS allows an...
CVE-2026-23622HIGH8.8Easy!Appointments is a self hosted appointment scheduler. In 1.5.2 and earlier, application/core/EA_Security.php::csrf_v...
CVE-2026-23520HIGH8Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane...
CVE-2026-22803HIGH7.5SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. From 2.49.0 to 2.49.4,...
CVE-2026-22775HIGH7.5Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the ...
CVE-2026-22774HIGH7.5Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the ...
CVE-2026-0227HIGH7.5A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (...
CVE-2026-22265HIGH7.5Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to 8.2.8.2, command injecti...
CVE-2026-22646HIGH7.5Certain error messages returned by the application expose internal system details that should not be visible to end user...
CVE-2026-22644HIGH7.5Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft throu...
CVE-2026-0897HIGH7.5Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through ...
CVE-2026-22918HIGH8.2An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions thr...
CVE-2026-22917HIGH7.5Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service.
CVE-2026-22911HIGH7.5Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover cre...
CVE-2026-0421HIGH7A potential vulnerability was reported in the BIOS of L13 Gen 6, L13 Gen 6 2-in-1, L14 Gen 6, and L16 Gen 2 ThinkPads wh...
CVE-2026-23512HIGH7.8SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability wh...
CVE-2026-0861HIGH8.4Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C...
CVE-2026-23498HIGH7.2Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array a...
CVE-2026-22036HIGH7.5Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, the number of links in the decompression chain is ...
CVE-2026-22856HIGH8.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP threa...
CVE-2026-21889HIGH7.5Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server...
CVE-2026-22240HIGH7.5The vulnerability exists in BLUVOYIX due to an improper password storage implementation and subsequent exposure via unau...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now