2026 CVE Vulnerabilities

60,215 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56425HIGH8.8The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorizat...
CVE-2026-56424HIGH8.8MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong ent...
CVE-2026-56423HIGH8.8MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The af...
CVE-2026-54100HIGH8.3A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishe...
CVE-2026-54099HIGH8.8A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR au...
CVE-2026-42129HIGH7.7A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endp...
CVE-2026-28381HIGH8.1The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the da...
CVE-2026-12888LOW2An HTML injection vulnerability exists in the Google Chat webhook notification  sent by Thinkst Applied Research Canaryt...
CVE-2026-12602HIGH8.8Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assig...
CVE-2026-10601MEDIUM4.3A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach uni...
CVE-2026-10561CRITICAL10IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with...
CVE-2026-56422CRITICAL9.4Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (i...
CVE-2026-11373CRITICAL9.1Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for th...
CVE-2026-12863MEDIUM5.1An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using...
CVE-2026-12862MEDIUM5.1Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be...
CVE-2026-12581HIGH7.7EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a s...
CVE-2026-12580MEDIUM5.4EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attack...
CVE-2026-54665MEDIUM5.3Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an...
CVE-2026-44914HIGH7.2Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension componen...
CVE-2026-44913HIGH7.2Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2....
CVE-2026-44911MEDIUM6.3Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clie...
CVE-2026-8157HIGH8.8The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new u...
CVE-2026-7859MEDIUM5.3The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX action...
CVE-2026-6858HIGH7.1The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthen...
CVE-2026-4259HIGH7.1The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outp...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now