2026 CVE Vulnerabilities

61,320 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-47196HIGH8.4Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the automod add command trims user input but does not re...
CVE-2026-47195HIGH7.1Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands check only guild-level p...
CVE-2026-9266HIGH7A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial...
CVE-2026-11849CRITICAL9.8The  iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing una...
CVE-2026-11848HIGH7.9The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing una...
CVE-2026-50645HIGH7.5There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache...
CVE-2026-50634MEDIUM6.5A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was...
CVE-2026-50633HIGH8.1A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code exec...
CVE-2026-50632HIGH8.1A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache...
CVE-2026-50631HIGH7.4A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-u...
CVE-2026-50630MEDIUM6.5A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate res...
CVE-2026-50629MEDIUM5.3The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages wi...
CVE-2026-50628CRITICAL9.8A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly all...
CVE-2026-50627CRITICAL9.1The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tok...
CVE-2026-50623MEDIUM4.8An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 't...
CVE-2026-49875CRITICAL9.8Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary...
CVE-2026-48914MEDIUM6.7A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of...
CVE-2026-11847MEDIUM5.3The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Path Traversal vulnerability, allowi...
CVE-2026-11846HIGH8.1The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerabilit...
CVE-2026-11845HIGH8.6The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, al...
CVE-2026-11844MEDIUM6.9The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, all...
CVE-2026-12058MEDIUM5.3The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.
CVE-2026-11535CRITICAL9.4An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unaut...
CVE-2026-9271MEDIUM5.9Vulnerability Title
CVE-2026-9269LOW3.5The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some o...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now