2026 CVE Vulnerabilities

61,338 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45560MEDIUM6.1Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, wr...
CVE-2026-45559MEDIUM4.9Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ge...
CVE-2026-45558CRITICAL9.9Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th...
CVE-2026-45556CRITICAL9.9Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PO...
CVE-2026-45552CRITICAL9.9Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th...
CVE-2026-45550CRITICAL9.1Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PU...
CVE-2026-45549HIGH8.5Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ag...
CVE-2026-11884MEDIUM6.5A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definitions, the oc_superior...
CVE-2026-9758HIGH7.3Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to ...
CVE-2026-53442MEDIUM5.3Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before stor...
CVE-2026-53441MEDIUM5.4Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-prov...
CVE-2026-53440MEDIUM4.3Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet...
CVE-2026-53439MEDIUM4.3Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permis...
CVE-2026-53438MEDIUM4.3A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permi...
CVE-2026-53437MEDIUM4.3Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately...
CVE-2026-53436MEDIUM4.3Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately...
CVE-2026-53435HIGH8.8In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrar...
CVE-2026-52759MEDIUM6.7Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows at...
CVE-2026-52758HIGH8.8Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values dir...
CVE-2026-52757MEDIUM4.6Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function durin...
CVE-2026-52756MEDIUM6.5Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connection...
CVE-2026-52755HIGH8.4Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to ...
CVE-2026-52754HIGH8.8Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows...
CVE-2026-52753MEDIUM6.7Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded outp...
CVE-2026-52752HIGH8.4Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now