2026 CVE Vulnerabilities

64,868 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-12666HIGH8.1IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1...
CVE-2026-12358HIGH7.5IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of ...
CVE-2026-12355HIGH8.1IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1...
CVE-2026-12354HIGH7.5IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1...
CVE-2026-12150HIGH7IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1...
CVE-2026-12101HIGH8.1IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to i...
CVE-2026-11934HIGH7.2IBM Verify Identity Access could allow an administrator to execute additional commands they are not entitled to due to i...
CVE-2026-11929HIGH7.5IBM Security Verify Identity Access Reverse Proxy in certain configurations may provide weaker than expected cryptograph...
CVE-2026-11926HIGH7.5IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of ...
CVE-2026-11729HIGH8.5IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1...
CVE-2026-11728HIGH8.1IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1...
CVE-2026-91853HIGH7.4A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvp...
CVE-2026-89022HIGH7.4BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows ...
CVE-2026-81895HIGH7.2In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] withou...
CVE-2026-63443HIGH8.3Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10...
CVE-2026-59160HIGH8.8Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts it...
CVE-2026-58201HIGH8.7Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2...
CVE-2026-58200HIGH7.1Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, @jhb.software/payloa...
CVE-2026-55692HIGH7.5The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em...
CVE-2026-55691HIGH8.6The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em...
CVE-2026-55690HIGH7.5The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em...
CVE-2026-55149HIGH7.5Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in ...
CVE-2026-21588HIGH7.1This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9...
CVE-2026-21587HIGH7.1This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data...
CVE-2026-21586HIGH7.1This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now