2026 CVE Vulnerabilities

61,772 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-35076HIGH8.1The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insuffici...
CVE-2026-35075CRITICAL9.8An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full a...
CVE-2026-10722MEDIUM5.5A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go...
CVE-2026-47065CRITICAL9.8ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Ful...
CVE-2026-41032HIGH7.5It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some...
CVE-2026-4035HIGH7.7A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gatew...
CVE-2026-5078MEDIUM5.3Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization reque...
CVE-2026-50052LOW2.3In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to l...
CVE-2026-50031HIGH7.5ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Manag...
CVE-2026-10705LOW3.1A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/datafram...
CVE-2026-10704HIGH7.3A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the func...
CVE-2026-10703MEDIUM6.3A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the function CreateMessageRo...
CVE-2026-9516HIGH7.5Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter...
CVE-2026-9334HIGH7.3Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref i...
CVE-2026-10694HIGH7.3A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function i...
CVE-2026-10693MEDIUM6.3A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulner...
CVE-2026-9732MEDIUM4.3The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forger...
CVE-2026-7421MEDIUM4.4The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu...
CVE-2026-10692MEDIUM4.3A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_patte...
CVE-2026-10691MEDIUM4.3A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function o...
CVE-2026-10690MEDIUM6.3A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of ...
CVE-2026-44654HIGH8.1LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a sha...
CVE-2026-44653MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users...
CVE-2026-42507MEDIUM5.3When returning errors, functions in the net/textproto package would include its input as part of the error. This might a...
CVE-2026-42504HIGH7.5Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now