2026 CVE Vulnerabilities

62,760 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-23638MEDIUM6.5Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil...
CVE-2026-22872CRITICAL9.1Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin pri...
CVE-2026-10283MEDIUM6.3A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setti...
CVE-2026-10282MEDIUM5.3A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the function view of the fi...
CVE-2026-10281HIGH7.3A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of th...
CVE-2026-10280HIGH7.3A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted element is an unknown function of the file...
CVE-2026-10279MEDIUM6.3A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the ...
CVE-2026-10278MEDIUM6.3A vulnerability was determined in ishayoyo excel-mcp up to 1.0.2. Impacted is an unknown function of the file src/index....
CVE-2026-10277MEDIUM6.3A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affect...
CVE-2026-10276MEDIUM6.3A vulnerability has been found in hekmon8 Jenkins-server-mcp 0.1.0. This vulnerability affects the function jobPath of t...
CVE-2026-0072HIGH7.8In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission che...
CVE-2026-8643MEDIUM5.5pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute ...
CVE-2026-8501HIGH7.8Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode proc...
CVE-2026-46243HIGH7.1In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descripti...
CVE-2026-45701MEDIUM6.9Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6,...
CVE-2026-45267MEDIUM6.5Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed ...
CVE-2026-45266LOW3.5Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and 23.0.3, a low-privil...
CVE-2026-45264MEDIUM4.3Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18....
CVE-2026-45159LOW3.5Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1.16.0 to before 1.16...
CVE-2026-45157MEDIUM6.3Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a...
CVE-2026-45156HIGH8.1Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, ...
CVE-2026-45155LOW2.6Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.7 an...
CVE-2026-45154LOW2.6Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3.0, when a previous ...
CVE-2026-45153MEDIUM4.6Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlockin...
CVE-2026-45132CRITICAL10CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now