2026 CVE Vulnerabilities

61,030 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56216HIGH8.8Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that allows ap...
CVE-2026-56215HIGH8.7Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, whi...
CVE-2026-56214HIGH8.7Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC endpoints is_trial_org ...
CVE-2026-56213MEDIUM6.9Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURITY DEFINER ...
CVE-2026-56212MEDIUM5.1Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization secur...
CVE-2026-11551CRITICAL9.8The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in...
CVE-2026-56082HIGH8.7Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST...
CVE-2026-56081CRITICAL9.3Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound...
CVE-2026-56080MEDIUM6.9Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and...
CVE-2026-56079HIGH7.1Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-...
CVE-2026-56073CRITICAL9.4Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypa...
CVE-2026-50559HIGH7.5Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, ...
CVE-2026-50519HIGH7.5Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized at...
CVE-2026-49346HIGH7.1libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream wi...
CVE-2026-49337MEDIUM4.3libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265...
CVE-2026-49295HIGH7.1libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream c...
CVE-2026-48794LOW1.3Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o...
CVE-2026-48584HIGH8.8Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a networ...
CVE-2026-48582CRITICAL9.6Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
CVE-2026-48129MEDIUM6.5Kestra is an open-source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kes...
CVE-2026-47645HIGH8.8Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized atta...
CVE-2026-47203LOW2.9Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o...
CVE-2026-45480CRITICAL10Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-42895HIGH7.5Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut...
CVE-2026-32208MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an aut...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now