2026 CVE Vulnerabilities

57,052 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-23560CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-23559CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-23556CRITICAL9.4When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ...
CVE-2026-15189MEDIUM6.3A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23....
CVE-2026-15188MEDIUM6.3A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affect...
CVE-2026-15187MEDIUM4.3A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Publ...
CVE-2026-11404HIGH7.5Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello...
CVE-2026-60109HIGH8.7Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauth...
CVE-2026-60108HIGH8.7Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthentica...
CVE-2026-5005MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics...
CVE-2026-56292HIGH7.5Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing...
CVE-2026-54801HIGH8.6A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst...
CVE-2026-54800MEDIUM6.3A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst...
CVE-2026-54799HIGH8.4A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst...
CVE-2026-54798HIGH7.1A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst...
CVE-2026-60095MEDIUM6.9Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake func...
CVE-2026-60094MEDIUM6.9Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated ...
CVE-2026-4256HIGH8.2Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology ...
CVE-2026-15186MEDIUM6.3A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply...
CVE-2026-15185LOW3.3A vulnerability was determined in GPAC 26.03-DEV. This affects the function vobsub_read_idx of the file /src/media_tools...
CVE-2026-14261CRITICAL9.1A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation ...
CVE-2026-12879MEDIUM5.9An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google...
CVE-2026-12593HIGH8.7The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to en...
CVE-2026-12116CRITICAL9.8A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings,...
CVE-2026-15184LOW3.3A vulnerability was found in GNU LibreDWG up to 0.13.4. The impacted element is the function dwg_next_entity of the file...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now