2026 CVE Vulnerabilities

59,849 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-58012HIGH8.2A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` ...
CVE-2026-58011HIGH7.5A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the gli...
CVE-2026-58010HIGH8.2A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-seriali...
CVE-2026-53433HIGH7.5fzf is vulnerable to a Denial of Service (DoS) due to inefficient HTTP body processing in the --listen mode due to ineff...
CVE-2026-53432HIGH7.5fzf is vulnerable to Integer Overflow leading to crash in FuzzyMatchV2 function. When input line length is approximately...
CVE-2026-4629MEDIUM6.5A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability b...
CVE-2026-47105Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-44946HIGH7.4A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-t...
CVE-2026-14209MEDIUM4.3A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass secur...
CVE-2026-13474HIGH7.5Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Prof...
CVE-2026-12388MEDIUM6.5A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user informati...
CVE-2026-10817HIGH7.5Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is ...
CVE-2026-10816HIGH7.5Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management I...
CVE-2026-8402CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electroni...
CVE-2026-57082MEDIUM5.9Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG...
CVE-2026-57081HIGH7.5Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecod...
CVE-2026-57080HIGH7.5Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length ...
CVE-2026-57079MEDIUM5.3Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-sup...
CVE-2026-53692MEDIUM5.9Redeight CMS version 1.0 uses the MD5 algorithm without a salt to store user passwords. Because MD5 is a cryptographical...
CVE-2026-53691HIGH8.6An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote C...
CVE-2026-53690CRITICAL9.3An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/inde...
CVE-2026-41053HIGH8.8Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused ...
CVE-2026-14162CRITICAL9.8Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated...
CVE-2026-14161HIGH8.7Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated...
CVE-2026-13766CRITICAL9.8DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL buil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now