2026 CVE Vulnerabilities

63,153 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49375MEDIUM6.1In JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page
CVE-2026-49374HIGH7.6In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
CVE-2026-49373HIGH8.8In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
CVE-2026-49372HIGH7.5In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible
CVE-2026-49371HIGH8.2In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
CVE-2026-49370HIGH7.5In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
CVE-2026-49369MEDIUM4.3In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages
CVE-2026-49368MEDIUM5.4In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
CVE-2026-49367HIGH8.8In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
CVE-2026-49366HIGH7.8In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
CVE-2026-47745MEDIUM6.5Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carrie...
CVE-2026-47744CRITICAL9.9Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings al...
CVE-2026-47742MEDIUM6.5Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (E...
CVE-2026-47741MEDIUM5.9Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the ...
CVE-2026-47740HIGH8.1Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Or...
CVE-2026-46372HIGH8.5SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-46344MEDIUM5.3liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prio...
CVE-2026-44652MEDIUM6.9SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-44651MEDIUM6.9SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-44650CRITICAL9.1SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-44649CRITICAL9.8SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-44648HIGH7.5SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-44611MEDIUM5.9Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is su...
CVE-2026-44518MEDIUM5.3liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prio...
CVE-2026-42951MEDIUM5.9An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes accoun...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now