2026 CVE Vulnerabilities

61,683 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45777CRITICAL9.8OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version ...
CVE-2026-45776MEDIUM4.3OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's...
CVE-2026-45758CRITICAL9.6Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, ...
CVE-2026-45300HIGH7.4The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT...
CVE-2026-25624MEDIUM4.8An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista E...
CVE-2026-25623HIGH7An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Mana...
CVE-2026-25622HIGH7A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Ge...
CVE-2026-25621HIGH7A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Fire...
CVE-2026-25620HIGH7An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge ...
CVE-2026-11420CRITICAL9.8Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauth...
CVE-2026-11419HIGH8.8A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper val...
CVE-2026-11414CRITICAL9.8A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Beca...
CVE-2026-11401HIGH8.6An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL w...
CVE-2026-11400HIGH8.6An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL...
CVE-2026-5415HIGH8.8The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for Wor...
CVE-2026-5411HIGH8.8The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for Wor...
CVE-2026-46511HIGH8.7HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing ...
CVE-2026-46496CRITICAL9.3HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability e...
CVE-2026-46399CRITICAL9.4HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0 ...
CVE-2026-46396CRITICAL9.3HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability e...
CVE-2026-46395CRITICAL9.3HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` functio...
CVE-2026-46394HIGH7.7HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an OS command injection vu...
CVE-2026-46393HIGH7.1HAX CMS helps manage microsite universe with PHP or NodeJs backends. An authenticated Server-Side Request Forgery (SSRF)...
CVE-2026-46392HIGH8.7HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFi...
CVE-2026-46391HIGH8.7HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 9.0.1 and prior to version 26.0...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now