2026 CVE Vulnerabilities

59,295 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-14363CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foun...
CVE-2026-14265HIGH8.8Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 t...
CVE-2026-58517MEDIUM4.3Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension ...
CVE-2026-58451HIGH7.1Horde IMP before 7.0.1 contains a path traversal vulnerability in lib/Compose.php that allows authenticated attackers to...
CVE-2026-55628MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1....
CVE-2026-55597MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-26...
CVE-2026-55595MEDIUM4.7ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-55594MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-55577MEDIUM5.9ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-55510MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-53492CRITICAL9.6containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation impr...
CVE-2026-53489MEDIUM6.5containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plu...
CVE-2026-53467MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-53466MEDIUM6.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-51947CRITICAL9.8An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 a...
CVE-2026-50195CRITICAL9.9containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the ...
CVE-2026-50160CRITICAL10Hoppscotch is an API development ecosystem. In self-hosted deployments of hoppscotch-backend from version 2026.4.1 and e...
CVE-2026-49119HIGH8.7Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that all...
CVE-2026-47262MEDIUM5.5containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vuln...
CVE-2026-41121HIGH7.8Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Lin...
CVE-2026-38142MEDIUM6.5An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.0...
CVE-2026-14358MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun...
CVE-2026-13769MEDIUM6.8Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask ...
CVE-2026-13760HIGH7.3OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cdk-lib on all platfor...
CVE-2026-5051MEDIUM4.4HashiCorp Vault and Vault Enterprise prior to 2.0.1 audit device validation logic did not consistently apply plugin dire...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now