2026 CVE Vulnerabilities

59,863 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-14160MEDIUM5.9Time-of-check time-of-use (TOCTOU) race condition vulnerability in Samsung Open Source Escargot allows Leveraging Race C...
CVE-2026-12114MEDIUM4.4The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2026-58302HIGH8.4rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads s...
CVE-2026-12243Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-8023HIGH7.5Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, ava...
CVE-2026-7656MEDIUM6.8The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) use...
CVE-2026-51219HIGH7.5A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows...
CVE-2026-51218HIGH7.5A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/core/s7_server.cpp) of snap7 v1.4.3 allows at...
CVE-2026-10648MEDIUM5.5mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src/serial_util.c calls net_buf_reset() on the result of sm...
CVE-2026-57997MEDIUM5.4Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not exp...
CVE-2026-51221HIGH7.5A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a D...
CVE-2026-34592HIGH7.7Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-10647MEDIUM5.3The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignores the return value of usbd_ep_enqueue()...
CVE-2026-55957HIGH7.3Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate...
CVE-2026-55956MEDIUM6.5Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ig...
CVE-2026-55955MEDIUM6.5Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the ...
CVE-2026-55276CRITICAL9.1Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisa...
CVE-2026-53434CRITICAL9.1Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connect...
CVE-2026-53404HIGH7.3Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first cond...
CVE-2026-50229MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example ...
CVE-2026-41896HIGH7.5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34597HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34594HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-13758LOW3.7CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt...
CVE-2026-57919HIGH7.8PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DA...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now