2026 CVE Vulnerabilities

60,195 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6458MEDIUM5.1Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authenticat...
CVE-2026-5818HIGH7.2Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) al...
CVE-2026-56785HIGH8.4FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email f...
CVE-2026-54588CRITICAL9.6Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacke...
CVE-2026-48493MEDIUM5.5Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PA...
CVE-2026-47693MEDIUM6.9Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable ...
CVE-2026-12164MEDIUM4.4Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or el...
CVE-2026-12163MEDIUM4.8Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-s...
CVE-2026-11972HIGH8.2When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly h...
CVE-2026-54518MEDIUM6.5jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...
CVE-2026-9073MEDIUM6.2A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitiv...
CVE-2026-56120Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-20...
CVE-2026-54517MEDIUM5.3jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...
CVE-2026-54516MEDIUM5.3jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...
CVE-2026-54515MEDIUM5.3jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...
CVE-2026-54514MEDIUM5.3jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...
CVE-2026-54513HIGH8.1jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...
CVE-2026-54512HIGH8.1jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...
CVE-2026-53931MEDIUM6.9NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the spreadsheet-import endpoint axiosRequ...
CVE-2026-53930MEDIUM5.1NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the base-migration endpoint accepted a ca...
CVE-2026-53929MEDIUM5.1NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, with NC_SECURE_ATTACHMENTS=true, an authe...
CVE-2026-53928MEDIUM6.3NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a stolen refresh token survived a passwor...
CVE-2026-53927MEDIUM5.1NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the spreadsheet-fetch endpoint (axiosRequ...
CVE-2026-53926MEDIUM6.3NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, revokeAllOAuthTokensByUser in the users s...
CVE-2026-50193HIGH7.5jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now