2026 CVE Vulnerabilities

61,293 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-47138HIGH8.7Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-42947HIGH8.8A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently...
CVE-2026-42932MEDIUM6.9Naxclow device identifiers use fixed manufacturing prefixes combined with sequential counters, producing a fully predict...
CVE-2026-42306HIGH7.2Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and ...
CVE-2026-41568MEDIUM6.1Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and ...
CVE-2026-28742CRITICAL9.8Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmwar...
CVE-2026-12143HIGH7.5form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argumen...
CVE-2026-12043HIGH8.8Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote ...
CVE-2026-10715MEDIUM5.1Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-...
CVE-2026-53406HIGH7.8Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0....
CVE-2026-48558CRITICAL10SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the ...
CVE-2026-48165HIGH7.2MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before ...
CVE-2026-48163HIGH7.2MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before ...
CVE-2026-47965HIGH7.8Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that...
CVE-2026-47225MEDIUM6Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is a cache isolation issue affe...
CVE-2026-47223MEDIUM5.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6....
CVE-2026-47216HIGH8.7Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is an unauthenticated denial-of...
CVE-2026-44173MEDIUM5.3MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before ...
CVE-2026-44172CRITICAL9.1MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taki...
CVE-2026-44171HIGH7.8MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before ...
CVE-2026-44170CRITICAL9.8MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before ...
CVE-2026-44169MEDIUM4.3MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 1...
CVE-2026-44168HIGH8MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before ...
CVE-2026-7387HIGH8.8Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to req...
CVE-2026-7184MEDIUM6.5Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API resp...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now