2026 CVE Vulnerabilities

61,786 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-30963LOW2.7Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved thr...
CVE-2026-23638MEDIUM6.5Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil...
CVE-2026-22872CRITICAL9.1Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin pri...
CVE-2026-10283MEDIUM6.3A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setti...
CVE-2026-10282MEDIUM5.3A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the function view of the fi...
CVE-2026-10281HIGH7.3A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of th...
CVE-2026-10280HIGH7.3A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted element is an unknown function of the file...
CVE-2026-10279MEDIUM6.3A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the ...
CVE-2026-10278MEDIUM6.3A vulnerability was determined in ishayoyo excel-mcp up to 1.0.2. Impacted is an unknown function of the file src/index....
CVE-2026-10277MEDIUM6.3A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affect...
CVE-2026-10276MEDIUM6.3A vulnerability has been found in hekmon8 Jenkins-server-mcp 0.1.0. This vulnerability affects the function jobPath of t...
CVE-2026-0072HIGH7.8In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission che...
CVE-2026-8643MEDIUM5.5pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute ...
CVE-2026-8501HIGH7.8Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode proc...
CVE-2026-46243HIGH7.1In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descripti...
CVE-2026-45701MEDIUM6.9Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6,...
CVE-2026-45267MEDIUM6.5Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed ...
CVE-2026-45266LOW3.5Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and 23.0.3, a low-privil...
CVE-2026-45264MEDIUM4.3Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18....
CVE-2026-45159LOW3.5Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1.16.0 to before 1.16...
CVE-2026-45157MEDIUM6.3Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a...
CVE-2026-45156HIGH8.1Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, ...
CVE-2026-45155LOW2.6Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.7 an...
CVE-2026-45154LOW2.6Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3.0, when a previous ...
CVE-2026-45153MEDIUM4.6Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlockin...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now