2026 CVE Vulnerabilities

57,083 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48316CRITICAL10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-43825HIGH7.3Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document c...
CVE-2026-40257MEDIUM5.5OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-40141CRITICAL9.9A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote ...
CVE-2026-40140HIGH7.5BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the ...
CVE-2026-40139CRITICAL9.8A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improp...
CVE-2026-40138HIGH8.1A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Pri...
CVE-2026-5268CRITICAL9.1An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products li...
CVE-2026-59196HIGH7.1pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoiste...
CVE-2026-59195HIGH8.2pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependenc...
CVE-2026-59194HIGH7.1pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patch...
CVE-2026-59152MEDIUM5LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can se...
CVE-2026-58203MEDIUM5.3pydantic-settings provides settings management using Pydantic. From 2.12.0 until 2.14.2, NestedSecretsSettingsSource rea...
CVE-2026-13122MEDIUM5.3OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service v...
CVE-2026-7185MEDIUM6A validation vulnerability has been identified in certain web features related to file management or upload in several p...
CVE-2026-58380HIGH7.8A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() ...
CVE-2026-54893LOW2.1URL path injection in the Microsoft Graph adapter of Swoosh. Swoosh.Adapters.MsGraph builds its Microsoft Graph API requ...
CVE-2026-13698HIGH7.5A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote a...
CVE-2026-13708HIGH7.5Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_...
CVE-2026-13705HIGH7.1Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bi...
CVE-2026-6901HIGH8.4Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P...
CVE-2026-6900CRITICAL9.1Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before...
CVE-2026-58226HIGH8.7Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax allows unauthenticated denial-of-service via unboun...
CVE-2026-56810HIGH8.7Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint (Mint.HTTP1 module) allows a deni...
CVE-2026-4249HIGH8.6The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now