2026 CVE Vulnerabilities

43,311 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-64259HIGH7.8In the Linux kernel, the following vulnerability has been resolved: fuse-uring: make a fuse_req on SQE commit only find...
CVE-2026-10818HIGH8.1The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1...
CVE-2026-66374HIGH8.1Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) rece...
CVE-2026-66373HIGH7.5Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code executio...
CVE-2026-61892HIGH8.8Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.
CVE-2026-61886HIGH7.1Weintek cMT3092X HMI stores user account passwords in plaintext.
CVE-2026-60135HIGH7.1An attacker can modify data that should be restricted to read‑only access.
CVE-2026-60134HIGH8.8Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.
CVE-2026-66041HIGH7.8FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc fil...
CVE-2026-66040HIGH8.8FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and A...
CVE-2026-66039HIGH7.8FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decod...
CVE-2026-66036HIGH8.8FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter...
CVE-2026-62835HIGH7.5Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
CVE-2026-54342HIGH8.1In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensyste...
CVE-2026-48036HIGH8.4Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-48035HIGH7.1Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-48034HIGH8.5Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-48033HIGH8.4Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-48032HIGH8.3Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. P...
CVE-2026-17107HIGH8.5A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes...
CVE-2026-66035HIGH7.7libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that a...
CVE-2026-66034HIGH7.7libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious S...
CVE-2026-66033HIGH8.7libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ss...
CVE-2026-66032HIGH8.8libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src...
CVE-2026-65711HIGH8.6sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now