2026 CVE Vulnerabilities

65,279 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-97395——Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set Fil...
CVE-2026-86450HIGH7.5Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix...
CVE-2026-81569——An improper authorization vulnerability exists in the handling of sub-workflow tasks. An authenticated user who does not...
CVE-2026-78214——An authentication bypass vulnerability exists in the protection of Actuator endpoints. The application determines whethe...
CVE-2026-71899——A missing authorization vulnerability exists in the `query-dynamic-sub-workflows` API of Apache DolphinScheduler. The AP...
CVE-2026-71898——An incorrect authorization check in Apache DolphinScheduler allows an authenticated user with only read permission for a...
CVE-2026-71897——An improper authorization check in Apache DolphinScheduler allows an authenticated user to use the batch-copy and batch-...
CVE-2026-4034HIGH8.7Injection Vulnerability in Tibco Administrator version 5.13.0 & prior allows an authenticated user to submit specially c...
CVE-2026-102521HIGH8.6The decoder in `readFromDataView` in lib0 before 0.2.119 can be tricked into reading more than it should from a buffer. ...
CVE-2026-102360HIGH8.6A missing bounds check in the binary decoder in lib0, versions 0.2.1-0.2.117 and earlier and 1.0.0-rc.32 and earlier, le...
CVE-2026-98164——In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Check write tracking in all address s...
CVE-2026-96869——Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and ...
CVE-2026-82973CRITICAL9.4Improper neutralization of CRLF sequences in IMAP command construction in psyb0t/docker-mailbox before 0.4.13 allows a r...
CVE-2026-82804——The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharac...
CVE-2026-7193HIGH8.6A vulnerability relating to the use of predefined credentials in the Dbit T-CPE301K 4G WiFi mini-router allows an attack...
CVE-2026-7192CRITICAL9.3A stack-based buffer overflow vulnerability in the Dbit T-CPE301K 4G WiFi minirouter allows an authenticated attacker to...
CVE-2026-76875MEDIUM5.3PyPy before versions 3.11.16 and 3.12.14 contains a use-after-free vulnerability in the pyexpat module's ExternalEntityP...
CVE-2026-76114MEDIUM5.9Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sen...
CVE-2026-73599MEDIUM5.4Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted...
CVE-2026-73598HIGH7.8Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignm...
CVE-2026-102437HIGH7.8OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasoni...
CVE-2026-101271LOW2.1OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth client) t...
CVE-2026-101270LOW2.1Malicious HTML content could be injected into the help texts of various fields with organizer permissions.
CVE-2026-101269LOW2.3The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same s...
CVE-2026-101268LOW1.7If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attacker's custo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now