2026 CVE Vulnerabilities

60,243 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44663HIGH7.1OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in...
CVE-2026-43994CRITICAL9.8Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.10.0 contain a stack buffer ove...
CVE-2026-56099MEDIUM5.3OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function wi...
CVE-2026-48983MEDIUM5.8pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, a symlink...
CVE-2026-48982MEDIUM5.8pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, when upda...
CVE-2026-48981MEDIUM6.7pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, pam_usb c...
CVE-2026-48980MEDIUM6.3pam_usb provides hardware authentication for Linux using removable media. In versions prior to 0.9.2, getenv() environm...
CVE-2026-48716HIGH8.7nanobot is a personal AI assistant. In versions 0.1.5.post3 and prior, the WhatsApp bridge in bridge/src/whatsapp.ts con...
CVE-2026-47847MEDIUM5.3Bitnami MariaDB Galera container images and Helm chart are affected by a hardcoded default credential vulnerability in t...
CVE-2026-47846CRITICAL9.8Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrat...
CVE-2026-43915MEDIUM5.4Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contain a stored cross-sit...
CVE-2026-2842Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-25865HIGH8.5Punto Switcher through 4.5.0.583 contains an unquoted search path element vulnerability that allows local attackers to e...
CVE-2026-9692MEDIUM5.3Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id ...
CVE-2026-55392MEDIUM6.7NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size ...
CVE-2026-48937HIGH7.5A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This v...
CVE-2026-47833MEDIUM6.9setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A comp...
CVE-2026-12390HIGH7.8In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using spe...
CVE-2026-54390CRITICAL9.8JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticate...
CVE-2026-48986MEDIUM4.7pam_usb provides hardware authentication for Linux using removable media. In pam_usb 0.9.1 and earlier, usb_get_process_...
CVE-2026-48985MEDIUM5.5pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, pusb_is_...
CVE-2026-48984MEDIUM4.7pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, the xfre...
CVE-2026-12475Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-56024MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue ...
CVE-2026-56022MEDIUM6.9Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now