2026 CVE Vulnerabilities

60,222 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56080MEDIUM6.9Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and...
CVE-2026-56079HIGH7.1Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-...
CVE-2026-56073CRITICAL9.4Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypa...
CVE-2026-50559HIGH7.5Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, ...
CVE-2026-50519HIGH7.5Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized at...
CVE-2026-49346HIGH7.1libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream wi...
CVE-2026-49337MEDIUM4.3libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265...
CVE-2026-49295HIGH7.1libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream c...
CVE-2026-48794LOW1.3Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o...
CVE-2026-48584HIGH8.8Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a networ...
CVE-2026-48582CRITICAL9.6Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
CVE-2026-48129MEDIUM6.5Kestra is an open-source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kes...
CVE-2026-47645HIGH8.8Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized atta...
CVE-2026-47203LOW2.9Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o...
CVE-2026-45480CRITICAL10Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-42895HIGH7.5Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut...
CVE-2026-32208MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an aut...
CVE-2026-49345MEDIUM5.3Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, ...
CVE-2026-49344HIGH7.1Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, ...
CVE-2026-49342MEDIUM5.3YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache ...
CVE-2026-48787HIGH7.4gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to t...
CVE-2026-48774HIGH7.5ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MC...
CVE-2026-48773CRITICAL9.8ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authenticat...
CVE-2026-48772CRITICAL10ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL ...
CVE-2026-48715HIGH8.8radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contai...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now