2026 CVE Vulnerabilities

57,072 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-13020CRITICAL9.8A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on ...
CVE-2026-13019CRITICAL9.8Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for crit...
CVE-2026-56812HIGH7.5Improper Check for Unusual or Exceptional Conditions vulnerability in phoenixframework phoenix (Presence JavaScript clie...
CVE-2026-56811HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix (Phoenix.Socket module) a...
CVE-2026-14969MEDIUM4.4A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vecto...
CVE-2026-14935LOW3.7A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverte...
CVE-2026-59709MEDIUM5.3Ghostfolio's PUT /api/v1/portfolio/holding/:dataSource/:symbol/tags endpoint fails to verify Access.permissions field wh...
CVE-2026-53878MEDIUM6.1An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlin...
CVE-2026-53877MEDIUM6.3An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `django.contrib.gis.gdal.GDALRaster` over-read...
CVE-2026-48588MEDIUM5.3An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()`...
CVE-2026-14940MEDIUM5.3A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) ...
CVE-2026-12948MEDIUM4.8A stored cross-site scripting (XSS) vulnerability in the web management interface of the Digi PortServer TS, Digi One SP...
CVE-2026-12352MEDIUM5.9This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on t...
CVE-2026-6101HIGH7.5The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to a...
CVE-2026-53479HIGH7.2Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-44938HIGH8.8A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from na...
CVE-2026-53483CRITICAL9.8Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-53481CRITICAL9.8Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-10659MEDIUM4.7The Dhara flash translation layer disk driver (drivers/disk/ftl_dhara.c) implemented the dhara_nand_ callbacks so that, ...
CVE-2026-13696HIGH8.8Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc. Lima...
CVE-2026-11348HIGH8.1Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data...
CVE-2026-11340HIGH8.3Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained b...
CVE-2026-49487MEDIUM6.5In Apache Airflow before 3.3.0, the REST API task-instance detail and list endpoints returned a deferred task's trigger ...
CVE-2026-49296MEDIUM6.5Before apache-airflow 3.3.0, a user authorized to read one Dag could disclose the source of other Dags co-located in the...
CVE-2026-48892MEDIUM6.5The Config API in Apache Airflow surfaced per-key secrets-backend overrides (environment variables like `AIRFLOW__SECRET...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now