2026 CVE Vulnerabilities

64,889 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-13285HIGH7.1IBM MQ is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could ...
CVE-2026-13275HIGH7.1IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1...
CVE-2026-13260HIGH7.5IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of ...
CVE-2026-13107HIGH7.1IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to X...
CVE-2026-82028HIGH8.8Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API serv...
CVE-2026-73496HIGH7.7MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, th...
CVE-2026-65838HIGH8.2Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.35, the opaAuthorizeRequestWithBody f...
CVE-2026-54632HIGH7.5SIPSorcery is a WebRTC, SIP, and VoIP library for C# and .NET. Prior to 10.0.9, RTPChannel.OnRTPPacketReceived and the S...
CVE-2026-54629HIGH7.5Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtu...
CVE-2026-54628HIGH8.6Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtu...
CVE-2026-54447HIGH8.4garminconnect is a Python 3 API wrapper for Garmin Connect that retrieves statistics and manages activities. Prior to 0....
CVE-2026-47253HIGH7.3Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar functi...
CVE-2026-19816HIGH7.1A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (...
CVE-2026-19624HIGH7.8A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and v...
CVE-2026-17467HIGH8.2IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due t...
CVE-2026-17416HIGH7.8IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to ex...
CVE-2026-17156HIGH7.8IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to ex...
CVE-2026-17133HIGH7.8IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to ex...
CVE-2026-16673HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitra...
CVE-2026-16466HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitra...
CVE-2026-16432HIGH7.7IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticated attacke...
CVE-2026-16428HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitra...
CVE-2026-16335HIGH8.1IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or...
CVE-2026-15955HIGH7.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file writ...
CVE-2026-90809HIGH7.3A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_comman...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now