2026 CVE Vulnerabilities

60,364 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-20190HIGH7.5A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information o...
CVE-2026-20181CRITICAL9.1A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on ...
CVE-2026-1288MEDIUM5.5A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL...
CVE-2026-12515MEDIUM4.3A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization chec...
CVE-2026-12151HIGH7.5Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but d...
CVE-2026-55748MEDIUM6OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name ...
CVE-2026-55743CRITICAL9.6The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised sec...
CVE-2026-54812CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Mot...
CVE-2026-54810HIGH7.5Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control S...
CVE-2026-54415HIGH8.6Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all pla...
CVE-2026-49502HIGH8.1Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthentic...
CVE-2026-48142MEDIUM6.3NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or p...
CVE-2026-48117MEDIUM6.8DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an a...
CVE-2026-47103CRITICAL9.8Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to ...
CVE-2026-42530CRITICAL9.2NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the ...
CVE-2026-42055HIGH8.1NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. ...
CVE-2026-40641MEDIUM4.8Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vuln...
CVE-2026-35162MEDIUM6.5Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg...
CVE-2026-35067HIGH8Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg...
CVE-2026-35066HIGH7.1Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg...
CVE-2026-35065HIGH8.8Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vulnerabi...
CVE-2026-32804HIGH8.1Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthentic...
CVE-2026-22283HIGH7.5Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted Control Sph...
CVE-2026-12528MEDIUM5.4A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Acce...
CVE-2026-11311MEDIUM6.5When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now