2026 CVE Vulnerabilities

67,120 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56737HIGH8.1phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authentication bypass in its pub...
CVE-2026-97404CRITICAL9.2In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty...
CVE-2026-97362HIGH7.5HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause...
CVE-2026-97224MEDIUM4.3A vulnerability was detected in Excalidraw up to 0.18.1. The impacted element is an unknown function of the file package...
CVE-2026-90959HIGH8.1A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows ...
CVE-2026-90481CRITICAL9.2In PortSwigger Burp Suite DAST (formerly Burp Suite Enterprise Edition) before 2026.8, an authentication bypass can occu...
CVE-2026-88351CRITICAL9.8An integer overflow vulnerability exists in the MPack Node API in MPack 1.1.1 on 32-bit platforms. When parsing a specia...
CVE-2026-82094HIGH7.1IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the s...
CVE-2026-82093HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to...
CVE-2026-81552HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-81549CRITICAL9.6IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ...
CVE-2026-81548HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-81547HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-81545HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-81539HIGH8.8IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to...
CVE-2026-77874HIGH8.6IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection....
CVE-2026-77825MEDIUM4.9IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint...
CVE-2026-77707MEDIUM5.9Improper certificate validation vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM)...
CVE-2026-77703MEDIUM5.9Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Mi...
CVE-2026-73064LOW2.9In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove o...
CVE-2026-6544MEDIUM6.2IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to uninte...
CVE-2026-65422MEDIUM6.5A flaw in the authorization mechanism for Media Gateway API in Genetec Security Center may allow a user with no playback...
CVE-2026-58008HIGH8.1Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured...
CVE-2026-58007HIGH8.1Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configur...
CVE-2026-58006HIGH8.1Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configur...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now