2026 CVE Vulnerabilities

61,338 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48855MEDIUM6.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows Fil...
CVE-2026-48096MEDIUM5.3OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is en...
CVE-2026-46558HIGH8.3Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization ...
CVE-2026-46497LOW2.3Crawlee is a web scraping and browser automation library. From version 1.0.0 to before version 1.7.0, Crawlee is vulnera...
CVE-2026-45569HIGH8.1Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, om...
CVE-2026-45567HIGH8.3Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th...
CVE-2026-45566MEDIUM6.1Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th...
CVE-2026-45565HIGH8.1Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, Es...
CVE-2026-25700HIGH7.2Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: thr...
CVE-2026-9045HIGH8.5During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manag...
CVE-2026-8637HIGH8.5A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could a...
CVE-2026-8335HIGH7.1A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute a...
CVE-2026-7516MEDIUM5.1A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese mark...
CVE-2026-6090HIGH7.3A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticate...
CVE-2026-53689HIGH7.1libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection ...
CVE-2026-53476CRITICAL9.6A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN),...
CVE-2026-53475HIGH7.4A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connecti...
CVE-2026-53474MEDIUM6.5A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a s...
CVE-2026-53473MEDIUM5.4A flaw was found in migration-planner-ui-app. An attacker can register a malicious discovery agent with a specially craf...
CVE-2026-53471HIGH7.7A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but...
CVE-2026-53470HIGH8.1A flaw was found in migration-planner. An authenticated attacker could exploit an improper access control vulnerability ...
CVE-2026-53469HIGH8.1A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request ...
CVE-2026-45564HIGH8.8Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PO...
CVE-2026-45563MEDIUM4.3Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, GE...
CVE-2026-45561MEDIUM6.5Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now