2026 CVE Vulnerabilities

66,554 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-79759MEDIUM4.3Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0...
CVE-2026-79758MEDIUM5.4Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0...
CVE-2026-77581HIGH8.6BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS pr...
CVE-2026-76907MEDIUM6.5LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 4.8.2 until 5.4.0, GET /api/v1.0/docum...
CVE-2026-75907HIGH7.5The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID s...
CVE-2026-67233MEDIUM6RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The shovel ma...
CVE-2026-63630LOW3.4BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Tim...
CVE-2026-63203HIGH7.6Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API han...
CVE-2026-56739HIGH8.5Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.43.0, Logto fetches administrator-...
CVE-2026-56737HIGH8.1phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authentication bypass in its pub...
CVE-2026-97404CRITICAL9.2In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty...
CVE-2026-97362HIGH7.5HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause...
CVE-2026-97224MEDIUM4.3A vulnerability was detected in Excalidraw up to 0.18.1. The impacted element is an unknown function of the file package...
CVE-2026-90959HIGH8.1A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows ...
CVE-2026-90481CRITICAL9.2In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occu...
CVE-2026-88351CRITICAL9.8An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specia...
CVE-2026-82094HIGH7.1IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the s...
CVE-2026-82093HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to...
CVE-2026-81552HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-81549CRITICAL9.6IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ...
CVE-2026-81548HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-81547HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-81545HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-81539HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to...
CVE-2026-77874HIGH8.6IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now