2026 CVE Vulnerabilities

64,858 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-58502HIGH7.1githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow r...
CVE-2026-58485HIGH7.1mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through ...
CVE-2026-58483HIGH7.5mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through ...
CVE-2026-57441HIGH8.4MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.4, ...
CVE-2026-56829HIGH8.1Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantSto...
CVE-2026-56827HIGH8.1Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/src/Livewire/Pages/At...
CVE-2026-56825HIGH8.1Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Collection/Collecti...
CVE-2026-55225HIGH8Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. I...
CVE-2026-54549HIGH8.3Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, th...
CVE-2026-54547HIGH7.4Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.115, Au...
CVE-2026-54251HIGH8.7netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0...
CVE-2026-52484HIGH8.8An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary code...
CVE-2026-44300HIGH8.8OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpo...
CVE-2026-40058HIGH8.8CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability on...
CVE-2026-18115HIGH7.4Concrete CMS 9.2.0 to 9.5.2 did not enforce per-field edit_user_properties permissions on the REST API user write endpoi...
CVE-2026-18113HIGH7.5In Concrete CMS 9.0 to 9.5.2, the Top Navigation Bar block did not HTML-escape dropdown child page names before writing ...
CVE-2026-13210HIGH7.7GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 19.1.8, 19.2 before 19.2.6, and 1...
CVE-2026-12752HIGH7.1IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) atta...
CVE-2026-12728HIGH8.8IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1...
CVE-2026-12667HIGH7.1IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1...
CVE-2026-12666HIGH8.1IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1...
CVE-2026-12358HIGH7.5IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of ...
CVE-2026-12355HIGH8.1IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1...
CVE-2026-12354HIGH7.5IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1...
CVE-2026-12150HIGH7IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now