2026 CVE Vulnerabilities

61,122 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-53872HIGH8.7picklescan before 0.0.35 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to r...
CVE-2026-3490CRITICAL10picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolv...
CVE-2026-36418CRITICAL9.1JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressi...
CVE-2026-35069HIGH8Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in a...
CVE-2026-35068MEDIUM5.7Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in a...
CVE-2026-32652HIGH7.8Dell AIOps Collector versions prior to 1.18.3 contain a "Use of Default Credentials" vulnerability. A low privileged att...
CVE-2026-20246MEDIUM6A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to e...
CVE-2026-20220MEDIUM6.3A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenti...
CVE-2026-20190HIGH7.5A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information o...
CVE-2026-20181CRITICAL9.1A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on ...
CVE-2026-1288MEDIUM5.5A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL...
CVE-2026-12515MEDIUM4.3A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization chec...
CVE-2026-12151HIGH7.5Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but d...
CVE-2026-55748MEDIUM6OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name ...
CVE-2026-55743CRITICAL9.6The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised sec...
CVE-2026-54812CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Mot...
CVE-2026-54810HIGH7.5Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control S...
CVE-2026-54415HIGH8.6Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all pla...
CVE-2026-49502HIGH8.1Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthentic...
CVE-2026-48142MEDIUM6.3NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or p...
CVE-2026-48117MEDIUM6.8DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an a...
CVE-2026-47103CRITICAL9.8Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to ...
CVE-2026-42530CRITICAL9.2NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the ...
CVE-2026-42055HIGH8.1NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. ...
CVE-2026-40641MEDIUM4.8Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vuln...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now