2026 CVE Vulnerabilities

59,898 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-43663MEDIUM6.5The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7...
CVE-2026-39872MEDIUM6.5The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7...
CVE-2026-39868CRITICAL9.1This issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5...
CVE-2026-37637CRITICAL9.1An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php compon...
CVE-2026-31016MEDIUM6.5Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escal...
CVE-2026-28979MEDIUM6.5An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 18....
CVE-2026-13763CRITICAL9.8Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote ...
CVE-2026-13762CRITICAL9.8Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to by...
CVE-2026-13593MEDIUM6.5CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. The minif...
CVE-2026-13008Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-57700. Reason: This candidate is a ...
CVE-2026-58000HIGH8.8luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKe...
CVE-2026-57999HIGH8.8luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows...
CVE-2026-53428MEDIUM6.9Memory Allocation with Excessive Size Value vulnerability in leandrocp mdex allows an unauthenticated attacker to cause ...
CVE-2026-53427LOW2.3Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leandrocp MDEx all...
CVE-2026-13757MEDIUM6.2A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_mes...
CVE-2026-57960HIGH8.3Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated acc...
CVE-2026-57959HIGH8.2Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before as...
CVE-2026-57958MEDIUM6.1Mixpost through 2.6.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to e...
CVE-2026-57957MEDIUM4.7Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unau...
CVE-2026-57956MEDIUM6.4SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other org...
CVE-2026-57955HIGH8.5SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary C...
CVE-2026-57954MEDIUM5.3Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSorting...
CVE-2026-57953MEDIUM5.4Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to ...
CVE-2026-57952MEDIUM6.5Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_web...
CVE-2026-57951HIGH7.1Mythic before 3.4.0.60 contains a broken hasura permission filter on the payload_build_step table with an always-satisfi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now