2026 CVE Vulnerabilities

59,898 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-55955MEDIUM6.5Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the ...
CVE-2026-55276CRITICAL9.1Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisa...
CVE-2026-53434CRITICAL9.1Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connect...
CVE-2026-53404HIGH7.3Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first cond...
CVE-2026-50229MEDIUM6.1Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example ...
CVE-2026-41896HIGH7.5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34597HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34594HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-13758LOW3.7CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt...
CVE-2026-57919HIGH7.8PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DA...
CVE-2026-57498CRITICAL9.6Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-56018HIGH7.5JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory ...
CVE-2026-56017HIGH7.5JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful t...
CVE-2026-54889MEDIUM5.1Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in leandrocp mdex allows cross-site scri...
CVE-2026-54888MEDIUM6.9Uncontrolled Recursion vulnerability in leandrocp mdex allows denial of service via deeply nested Markdown input. mdex ...
CVE-2026-53429MEDIUM6.9Missing Release of Memory after Effective Lifetime vulnerability in leandrocp mdex and mdex_native allows an attacker wh...
CVE-2026-53426HIGH8.2Allocation of Resources Without Limits or Throttling vulnerability in leandrocp MDEx allows Excessive Allocation. MDEx....
CVE-2026-43746MEDIUM6.5A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 ...
CVE-2026-43745MEDIUM6.5An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18....
CVE-2026-43743MEDIUM4.7A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, iOS 26...
CVE-2026-43742MEDIUM6.5A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 ...
CVE-2026-43740MEDIUM6.5The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5....
CVE-2026-43735HIGH8.1The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS ...
CVE-2026-43734MEDIUM6.5A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 ...
CVE-2026-43732MEDIUM6.5A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadO...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now