2026 CVE Vulnerabilities

44,807 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-71391MEDIUM5.3GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index b...
CVE-2026-66642MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP...
CVE-2026-66486MEDIUM4.6GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When list...
CVE-2026-66485MEDIUM4.6GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function us...
CVE-2026-66484MEDIUM4.6GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar arch...
CVE-2026-65948HIGH7.3UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option f...
CVE-2026-65945MEDIUM6.5Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0,...
CVE-2026-65942HIGH7.5TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to v...
CVE-2026-61899HIGH7.5Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets v...
CVE-2026-59087HIGH7.8A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote...
CVE-2026-55814HIGH7.5Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version ...
CVE-2026-55799CRITICAL9.8Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgra...
CVE-2026-44416CRITICAL9.8Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. U...
CVE-2026-42537CRITICAL9.8Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0...
CVE-2026-40920CRITICAL9.8Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade...
CVE-2026-32227CRITICAL9.8SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to v...
CVE-2026-28672CRITICAL9.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. Thi...
CVE-2026-66915CRITICAL10Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute ar...
CVE-2026-44630HIGH7.5Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to caus...
CVE-2026-19404MEDIUM6.5A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operati...
CVE-2026-66411MEDIUM6.9DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unaut...
CVE-2026-66410MEDIUM4.8Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or alt...
CVE-2026-66409MEDIUM6.9DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password ma...
CVE-2026-66408MEDIUM5.1The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affec...
CVE-2026-66407HIGH8.1DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket privat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now