2026 CVE Vulnerabilities

61,049 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48986MEDIUM4.7pam_usb provides hardware authentication for Linux using removable media. In pam_usb 0.9.1 and earlier, usb_get_process_...
CVE-2026-48985MEDIUM5.5pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, pusb_is_...
CVE-2026-48984MEDIUM4.7pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, the xfre...
CVE-2026-12475Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-56024MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue ...
CVE-2026-56022MEDIUM6.9Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, a...
CVE-2026-56021MEDIUM6.9Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due ...
CVE-2026-56020CRITICAL9.2The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL clie...
CVE-2026-55237HIGH8.8AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-55205MEDIUM5.3Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oa...
CVE-2026-55204HIGH8.7HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert()...
CVE-2026-55203CRITICAL9.1HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's ...
CVE-2026-54106MEDIUM5.1The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac...
CVE-2026-54105MEDIUM6.9The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac...
CVE-2026-54104HIGH8.8The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac...
CVE-2026-54103CRITICAL9.8The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac...
CVE-2026-48617HIGH8.2A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This...
CVE-2026-38718HIGH7.5InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a bu...
CVE-2026-38717CRITICAL9.8InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co...
CVE-2026-38716CRITICAL9.8InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co...
CVE-2026-38715CRITICAL9.8InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co...
CVE-2026-38714CRITICAL9.8InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co...
CVE-2026-11982MEDIUM5.1Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages A...
CVE-2026-10687Rejected reason: This CVE Record has been rejected by the Zephyr Project CNA. Subsequent analysis, confirmed with the fi...
CVE-2026-46580HIGH8.8In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were auto...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now