2026 CVE Vulnerabilities

57,064 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3144CRITICAL9.8IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized ac...
CVE-2026-15063MEDIUM6.3A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication...
CVE-2026-14967LOW3.1BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory...
CVE-2026-14966LOW3.1BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it fa...
CVE-2026-59703HIGH8.7repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to...
CVE-2026-55874HIGH7.7SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in th...
CVE-2026-55873MEDIUM4.3SeaweedFS is a distributed storage system. In versions 4.08 through 4.33, requests signed with SigV4 service s3tables ar...
CVE-2026-55668MEDIUM6.3File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor ...
CVE-2026-54652HIGH8.1Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any aut...
CVE-2026-49147HIGH7.5App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output m...
CVE-2026-49146HIGH7.5App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc. ac...
CVE-2026-49145HIGH7.5App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up th...
CVE-2026-24700HIGH7.2An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with ...
CVE-2026-24699HIGH7.2An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with f...
CVE-2026-24698HIGH7.2An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/...
CVE-2026-24697HIGH7.2An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W wi...
CVE-2026-15067HIGH8.8Snowflake Terraform Provider versions prior to 2.18.0 contain several security vulnerabilities, including SQL injection ...
CVE-2026-15062CRITICAL9.6SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allo...
CVE-2026-15044MEDIUM6.3A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific s...
CVE-2026-15036MEDIUM4.3A vulnerability was determined in Harness up to 2.28.2. This vulnerability affects the function getAuthorizedSpaces of t...
CVE-2026-11903MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Tr...
CVE-2026-10708HIGH7.5This vulnerability enables large‑scale data harvesting without requiring app‑specific secrets. A single request to a min...
CVE-2026-10706HIGH7.5In Adalo’s no-code app builder, (Versions 1 and 2) the attackers may extract full user records and correlate user behavi...
CVE-2026-10699HIGH7.5Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modules). ...
CVE-2026-10698HIGH7.2Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Report...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now