2026 CVE Vulnerabilities

61,333 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7870HIGH8.8IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malici...
CVE-2026-7787HIGH8.1IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypass...
CVE-2026-53777HIGH8.6Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary co...
CVE-2026-4096MEDIUM6.1IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by th...
CVE-2026-3341MEDIUM5.4IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allo...
CVE-2026-11839CRITICAL9.9Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows ...
CVE-2026-8406HIGH7.1openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticate...
CVE-2026-6338MEDIUM4.9A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13...
CVE-2026-53723MEDIUM5.8Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to descri...
CVE-2026-53661HIGH8.8Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized iden...
CVE-2026-38581CRITICAL9.8SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitra...
CVE-2026-11816HIGH8.1Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `...
CVE-2026-10847HIGH7.8A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated lo...
CVE-2026-7852CRITICAL9.8Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclu...
CVE-2026-49214MEDIUM5.3guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII con...
CVE-2026-48998MEDIUM5.3guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host he...
CVE-2026-11956MEDIUM6.3A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc...
CVE-2026-11561CRITICAL9.8Improper neutralization of special elements used in an expression language statement ('expression language injection') v...
CVE-2026-9694MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, an...
CVE-2026-9204MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, a...
CVE-2026-8589HIGH8.7GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and...
CVE-2026-8464HIGH8.3Golem OEE MES is vulnerable to an unauthenticated path traversal flaw. This vulnerability allows an attacker in the same...
CVE-2026-7250HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, a...
CVE-2026-6976LOW3.7GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, an...
CVE-2026-6552Rejected reason: This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulne...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now