2026 CVE Vulnerabilities

64,889 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-53659HIGH7.5http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZ...
CVE-2026-50276HIGH7.5dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGG...
CVE-2026-50270HIGH7.5dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAG...
CVE-2026-49250HIGH8.7Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property. From ...
CVE-2026-34151HIGH8.2XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinActio...
CVE-2026-19499HIGH7.7Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied ou...
CVE-2026-84445HIGH8.7gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() ...
CVE-2026-76442HIGH7.5As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisc...
CVE-2026-61701HIGH8.8Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until...
CVE-2026-59960HIGH7.5Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.2.1, attacker-contro...
CVE-2026-57579HIGH7.5Alchemy is an open source content management system engine written in Ruby on Rails. Prior to 7.4.15, 8.0.15, 8.1.14, an...
CVE-2026-55451HIGH8.3gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2...
CVE-2026-55416HIGH8.8Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticat...
CVE-2026-55072HIGH8.5Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objec...
CVE-2026-54156HIGH7.5node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNon...
CVE-2026-54155HIGH7.7node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentic...
CVE-2026-90947HIGH7.8A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not...
CVE-2026-90943HIGH8.7parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering ...
CVE-2026-81301HIGH8.5Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider with...
CVE-2026-57132HIGH8.2PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token acc...
CVE-2026-57122HIGH8.6PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signa...
CVE-2026-57119HIGH7.5PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing...
CVE-2026-56839HIGH7.3PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass ...
CVE-2026-47701HIGH7.7The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocato...
CVE-2026-90789HIGH7.3A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown funct...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now