2026 CVE Vulnerabilities

44,088 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-52476HIGH7.5SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPage...
CVE-2026-52474HIGH7.5An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file.
CVE-2026-47697HIGH7.1Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace). ...
CVE-2026-47695HIGH7.1CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to version 1....
CVE-2026-47690HIGH7.5MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to ...
CVE-2026-47688HIGH8.2FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1....
CVE-2026-47687HIGH8.7FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1....
CVE-2026-47685HIGH8.7FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1....
CVE-2026-47237HIGH8Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to versio...
CVE-2026-44879HIGH7.2A vulnerability in the command line interface of ECOS devices could allow a highly privileged, authenticated remote atta...
CVE-2026-44878HIGH7.2A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated r...
CVE-2026-30633HIGH7.5Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools...
CVE-2026-16317HIGH8.3Missing validation of the outer content_type byte on TLS 1.3 encrypted records in s2n-tls allows an active man-in-the-mi...
CVE-2026-64880HIGH7.1Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper ...
CVE-2026-59146HIGH7.8Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, lin...
CVE-2026-56852HIGH7.5A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
CVE-2026-50759HIGH7.5An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instan...
CVE-2026-50758HIGH8.1Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary c...
CVE-2026-50757HIGH7.8Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary cod...
CVE-2026-50756HIGH7.5An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-pro...
CVE-2026-47667HIGH7.5CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field i...
CVE-2026-46600HIGH7.5Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.
CVE-2026-30632HIGH7.5Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.
CVE-2026-15957HIGH8.7Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface ...
CVE-2026-63454HIGH7.2An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now