2026 CVE Vulnerabilities

61,786 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-24751HIGH8.2Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Dat...
CVE-2026-10289MEDIUM4.3A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown fu...
CVE-2026-10288HIGH7.3A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the functio...
CVE-2026-10287HIGH7.3A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get...
CVE-2026-10286MEDIUM6.3A vulnerability was found in CodeAstro Payroll System 1.0. This affects an unknown part of the file /home_employee.php. ...
CVE-2026-10285MEDIUM5.4A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the functi...
CVE-2026-10284MEDIUM5.4A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the functio...
CVE-2026-9614HIGH8.8An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticate...
CVE-2026-9330HIGH8.5IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deseria...
CVE-2026-9319CRITICAL9IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of...
CVE-2026-9311CRITICAL9IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security co...
CVE-2026-8644CRITICAL9.1IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
CVE-2026-7770HIGH8.8IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution ...
CVE-2026-49121CRITICAL9.8AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the ...
CVE-2026-47294HIGH8Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoin...
CVE-2026-45810MEDIUM6.8Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, ...
CVE-2026-45729MEDIUM4.3Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer deref...
CVE-2026-45727HIGH8.8CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP multiplexer uses the u...
CVE-2026-45722HIGH7.1Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0...
CVE-2026-45691MEDIUM5.9Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a...
CVE-2026-45690MEDIUM5.9Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a...
CVE-2026-45545HIGH8.2Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10,...
CVE-2026-45544MEDIUM4.3Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter ...
CVE-2026-45543MEDIUM5.3Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collab...
CVE-2026-45302HIGH8.2parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now