2026 CVE Vulnerabilities

43,031 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-73325HIGH7.8Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers t...
CVE-2026-73293HIGH8.8Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ...
CVE-2026-73292HIGH8.3Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accep...
CVE-2026-69105HIGH8.1An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affe...
CVE-2026-68759HIGH7.2A holder of a valid integration credential may impersonate other users under specific conditions.
CVE-2026-67260HIGH7.3Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the ...
CVE-2026-65941HIGH8.8In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affecte...
CVE-2026-65937HIGH8In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject per...
CVE-2026-15803HIGH8.7In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsin...
CVE-2026-73431HIGH8.8Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Ac...
CVE-2026-73291HIGH7.1Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr'...
CVE-2026-73289HIGH8.1RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: ...
CVE-2026-73286HIGH8.1RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds a...
CVE-2026-73285HIGH7.5RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA a...
CVE-2026-73284HIGH8.8RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/servi...
CVE-2026-73264HIGH7.6Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration acce...
CVE-2026-68757HIGH7.5A user with access to a valid SAML response may impersonate another user under specific conditions.
CVE-2026-68752HIGH7.2A Project Resource Manager may gain broader administrative privileges under specific conditions.
CVE-2026-66375HIGH8.1A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific...
CVE-2026-14478HIGH7.8A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to in...
CVE-2026-47231HIGH8.1Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-c...
CVE-2026-70468HIGH8.1A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7....
CVE-2026-57858HIGH8.9Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagMa...
CVE-2026-53996HIGH7.3NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unpr...
CVE-2026-70465HIGH8.1A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now