2026 CVE Vulnerabilities

66,316 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-97323MEDIUM6.3A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOrigina...
CVE-2026-97322MEDIUM4.3A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the f...
CVE-2026-97321MEDIUM6.3A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function...
CVE-2026-97320MEDIUM6.3A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowle...
CVE-2026-96749HIGH8.4An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may ...
CVE-2026-96748MEDIUM6.5PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separ...
CVE-2026-96747MEDIUM5The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value en...
CVE-2026-89325HIGH7.8An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, l...
CVE-2026-86860CRITICAL9.3ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This ...
CVE-2026-86859HIGH8.7ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This...
CVE-2026-86858HIGH8.7ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. T...
CVE-2026-86857HIGH8.4ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This...
CVE-2026-85738MEDIUM6.3TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf logic in server/src/utils/ssrfGuard.ts does not re...
CVE-2026-82371HIGH8.5Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals wi...
CVE-2026-82157HIGH8.3Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerabil...
CVE-2026-81473HIGH8.1Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low priv...
CVE-2026-81455HIGH8.6Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function...
CVE-2026-77321MEDIUM4.3TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is re...
CVE-2026-77320MEDIUM5.3TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns...
CVE-2026-77294HIGH8.1TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlle...
CVE-2026-77293HIGH7.1TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId...
CVE-2026-65827MEDIUM6.5Docmost is open-source collaborative wiki and documentation software. From 0.21.0 until 0.95.0, any authenticated worksp...
CVE-2026-62286MEDIUM4.3Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go applies a...
CVE-2026-61825HIGH8.7code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before...
CVE-2026-61823HIGH7.3code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now