2026 CVE Vulnerabilities

57,052 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-55207HIGH8.8Pimcore is an Open Source Data & Experience Management Platform. Prior to 2025.4.6 and 2026.1.6, an unauthenticated atta...
CVE-2026-51926HIGH7.5An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php...
CVE-2026-51925HIGH8.1A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to exec...
CVE-2026-51924HIGH8.1An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and rep...
CVE-2026-51923HIGH8.1An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attac...
CVE-2026-33801HIGH7.1An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (RPD) of Juniper Ne...
CVE-2026-33800MEDIUM6.5An Unchecked Input for Loop Condition vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS o...
CVE-2026-33799MEDIUM5.3An Out-of-bounds Write vulnerability in the SNMP daemon (snmpd) of Juniper Networks Junos OS and Junos OS Evolved allows...
CVE-2026-33794HIGH8.2An Improper Check for Unusual or Exceptional Conditions vulnerability in the advanced forwarding toolkit (evo-aftmand)...
CVE-2026-31267MEDIUM5.7Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Overflow in the administrative web interface. ...
CVE-2026-21901MEDIUM4.4A NULL Pointer Dereference vulnerability in the management daemon (mgd) of Juniper Networks Junos OS and Junos OS Evolve...
CVE-2026-15270HIGH7.5A weakness has been identified in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functi...
CVE-2026-0278HIGH7.8Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow...
CVE-2026-0277MEDIUM5.9An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a ma...
CVE-2026-0276HIGH7.8A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to...
CVE-2026-0275MEDIUM6.7A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administ...
CVE-2026-59149MEDIUM6.5Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is ...
CVE-2026-59148HIGH8.8Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/...
CVE-2026-58198MEDIUM5.5ChatterBot is a machine learning, conversational dialog engine for creating chat bots. Prior to 1.2.14, UbuntuCorpusTrai...
CVE-2026-55590MEDIUM6.1CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior ...
CVE-2026-54695MEDIUM6.5Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Prior to 1...
CVE-2026-54005HIGH7.1Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.acce...
CVE-2026-54004MEDIUM6.3Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enab...
CVE-2026-54003CRITICAL9.1Kirby is an open-source content management system. Prior to 4.9.4 and from 5.4.4, Kirby sites with no configured user ac...
CVE-2026-54002HIGH8.5Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins that use the writer...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now