2026 CVE Vulnerabilities

59,849 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-58169HIGH7.7Vibe-Trading before 0.1.10 contains a DNS rebinding authentication bypass vulnerability that allows remote attackers to ...
CVE-2026-58168HIGH8.8DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke...
CVE-2026-58167HIGH7.1Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HT...
CVE-2026-58166CRITICAL9.1OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthentica...
CVE-2026-58165HIGH8.8OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated...
CVE-2026-49451HIGH7.5The OpenAPI.NET SDK contains a useful object model for OpenAPI documents in .NET along with common serializers to extrac...
CVE-2026-10655MEDIUM5.9The asynchronous SNTP client in Zephyr (subsys/net/lib/sntp/sntp.c, sntp_close_async) closed the UDP socket file descrip...
CVE-2026-10654LOW3.1A race condition in the Zephyr Bluetooth Classic RFCOMM host stack (subsys/bluetooth/host/classic/rfcomm.c) mishandles a...
CVE-2026-10653HIGH8.1The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf->ref and t...
CVE-2026-10652HIGH7.4Zephyr's DNS resolver (subsys/net/lib/dns) parses resource records from DNS responses in dns_unpack_answer(), which vali...
CVE-2026-48315CRITICAL9.3ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-48314MEDIUM6.5ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir...
CVE-2026-48313CRITICAL9.3ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir...
CVE-2026-48307HIGH8.8ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An...
CVE-2026-48286CRITICAL10Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerabil...
CVE-2026-48285HIGH8.6ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that ...
CVE-2026-48283CRITICAL10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulne...
CVE-2026-48282CRITICAL10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir...
CVE-2026-48281CRITICAL10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-48277CRITICAL10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-48276CRITICAL10ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulne...
CVE-2026-44948MEDIUM5.3A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up...
CVE-2026-13455MEDIUM4.3PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() ...
CVE-2026-4360MEDIUM5.3In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected sy...
CVE-2026-48192MEDIUM6.8A vulnerability has been identified in Mendix Studio Pro 10.11 (All versions), Mendix Studio Pro 10.12 (All versions), M...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now