2026 CVE Vulnerabilities

60,210 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12549MEDIUM4.8The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a gene...
CVE-2026-12479MEDIUM6.1A path traversal vulnerability exists in keras-team/keras version 3.14.0, specifically in the `DiskIOStore.make` method ...
CVE-2026-11943MEDIUM4.8Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on i...
CVE-2026-11942MEDIUM4.8Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the reusable delete confirmation...
CVE-2026-11372MEDIUM5.4IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an...
CVE-2026-10845HIGH7.3IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorize...
CVE-2026-9162MEDIUM4.3Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached ...
CVE-2026-9029MEDIUM5.4A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer ...
CVE-2026-8074LOW3.8Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user act...
CVE-2026-7167MEDIUM6.9The vulnerability arises when the system fails to properly validate the 'email' field during the authentication process,...
CVE-2026-7166CRITICAL9.2Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and p...
CVE-2026-7165CRITICAL9.4The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters a...
CVE-2026-6673MEDIUM6.4Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlas...
CVE-2026-6653CRITICAL9.8Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker ...
CVE-2026-6062MEDIUM6.4Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel o...
CVE-2026-5139MEDIUM5.4Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administra...
CVE-2026-56450MEDIUM5.1AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reac...
CVE-2026-56448HIGH8.3A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e4...
CVE-2026-56447HIGH7.2MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path...
CVE-2026-56446HIGH7.2MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool...
CVE-2026-56425HIGH8.8The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorizat...
CVE-2026-56424HIGH8.8MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong ent...
CVE-2026-56423HIGH8.8MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The af...
CVE-2026-54100HIGH8.3A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishe...
CVE-2026-54099HIGH8.8A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR au...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now