2026 CVE Vulnerabilities

44,078 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-46987HIGH7.7Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Applicatio...
CVE-2026-46981HIGH7.2Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mob...
CVE-2026-46954HIGH7.2Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Data Removal Tool). Supporte...
CVE-2026-46943HIGH7.4Vulnerability in the Oracle Retail EFTLink product of Oracle Retail Applications (component: Core/Plugin). Supported ve...
CVE-2026-46941HIGH7.5Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Maintenance). Supported...
CVE-2026-46923HIGH8Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Auth...
CVE-2026-43947HIGH8.9FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an unauthenticated Remote Co...
CVE-2026-43946HIGH7.7FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Version 1.3.0 has an authorization bypass in t...
CVE-2026-43945HIGH8.9FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthent...
CVE-2026-35287HIGH7.5Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploita...
CVE-2026-16484HIGH7.3A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unkn...
CVE-2026-10680HIGH7.6The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/bluetooth/host/class...
CVE-2026-10678HIGH8.1The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writ...
CVE-2026-8982HIGH8.1Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vend...
CVE-2026-65056HIGH8.3mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal netw...
CVE-2026-65054HIGH8.2MediaCMS 8.2.0 contains an information disclosure vulnerability that allows authenticated users to expose private media ...
CVE-2026-64881HIGH8.8The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command exe...
CVE-2026-63764HIGH8.6LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _lo...
CVE-2026-63358HIGH8.4FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to P...
CVE-2026-63080HIGH7.1Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authe...
CVE-2026-56147HIGH7.1Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and...
CVE-2026-52476HIGH7.5SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPage...
CVE-2026-52474HIGH7.5An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file.
CVE-2026-47697HIGH7.1Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace). ...
CVE-2026-47695HIGH7.1CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to version 1....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now