2026 CVE Vulnerabilities

64,751 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-82164HIGH7.1Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resourc...
CVE-2026-77967HIGH8.1The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshnes...
CVE-2026-96749HIGH8.4An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may ...
CVE-2026-89325HIGH7.8An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, l...
CVE-2026-86859HIGH8.7ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This...
CVE-2026-86858HIGH8.7ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. T...
CVE-2026-86857HIGH8.4ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This...
CVE-2026-82371HIGH8.5Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals wi...
CVE-2026-82157HIGH8.3Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerabil...
CVE-2026-81473HIGH8.1Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low priv...
CVE-2026-81455HIGH8.6Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function...
CVE-2026-77294HIGH8.1TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlle...
CVE-2026-77293HIGH7.1TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId...
CVE-2026-61825HIGH8.7code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before...
CVE-2026-61823HIGH7.3code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before...
CVE-2026-57440HIGH7.5The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em...
CVE-2026-48070HIGH7.1Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store att...
CVE-2026-13248HIGH8.8An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerabil...
CVE-2026-95985HIGH8.8The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject craft...
CVE-2026-85057HIGH8.7ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables t...
CVE-2026-85056HIGH8.2ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser sess...
CVE-2026-71540HIGH7.5Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. F...
CVE-2026-63645HIGH7.5OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoin...
CVE-2026-61816HIGH7.5zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading mess...
CVE-2026-61815HIGH7.2zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading mess...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now