2026 CVE Vulnerabilities

64,889 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-82438HIGH8.1Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP com...
CVE-2026-82432HIGH8.1Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalanc...
CVE-2026-82430HIGH7.8Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the ent...
CVE-2026-82429HIGH7.8Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking...
CVE-2026-82428HIGH8.8Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from t...
CVE-2026-82427HIGH7.8Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervi...
CVE-2026-7848HIGH8.6Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the "hookActionObjectProdu...
CVE-2026-59570HIGH7.5On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user ...
CVE-2026-59569HIGH8.1An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to pot...
CVE-2026-57130HIGH8.1PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/ema...
CVE-2026-57129HIGH7.5PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts f...
CVE-2026-57126HIGH8.5PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_block...
CVE-2026-25687HIGH8.1A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corrupti...
CVE-2026-15600HIGH8.6Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotio...
CVE-2026-90949HIGH7.8A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-base...
CVE-2026-90948HIGH7.8A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer ove...
CVE-2026-90787HIGH7.3A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is ...
CVE-2026-73236HIGH7.5Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks are based on Realm ...
CVE-2026-73195HIGH7.3Improper Encoding or Escaping of Output vulnerability in Apache Syncope. Authenticated users can store a spreadsheet ...
CVE-2026-90938HIGH8.6LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/p...
CVE-2026-90933HIGH7.1laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allow...
CVE-2026-90932HIGH7.2LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. C...
CVE-2026-90929HIGH8.1File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (res...
CVE-2026-90715HIGH7.3A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the ...
CVE-2026-78336HIGH7.5Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query f...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now