2026 CVE Vulnerabilities

57,114 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-58467HIGH8.2Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated ...
CVE-2026-58466CRITICAL9.8AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers t...
CVE-2026-58381MEDIUM6.1A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function whe...
CVE-2026-52187HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-7311HIGH8.1The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to in...
CVE-2026-58465HIGH8.7Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 hand...
CVE-2026-13743LOW3.3CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 are vulnerable to an Improper Verification of Cryptogr...
CVE-2026-8699HIGH7A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5...
CVE-2026-55952HIGH7.5The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientH...
CVE-2026-55950MEDIUM5.9Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an u...
CVE-2026-54891LOW3.7Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Erlang/OTP ssl...
CVE-2026-54887MEDIUM4.8Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DTLS cookie computatio...
CVE-2026-54886MEDIUM4.3Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an auth...
CVE-2026-53422MEDIUM4.3Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to ...
CVE-2026-50282MEDIUM4.9Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and...
CVE-2026-50281HIGH7.1Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw...
CVE-2026-44935CRITICAL9.9Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.1...
CVE-2026-58455CRITICAL9.8Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to...
CVE-2026-44941HIGH8.8A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attack...
CVE-2026-9272HIGH8.1In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenti...
CVE-2026-8079HIGH7.3In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged...
CVE-2026-56842HIGH7.5A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulne...
CVE-2026-56841HIGH8.8A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerabili...
CVE-2026-56004CRITICAL10A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by ...
CVE-2026-55119HIGH8.1A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability f...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now