2026 CVE Vulnerabilities

67,198 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-66072MEDIUM6RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, get_chunk_sel...
CVE-2026-66069LOW2.3RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.13, 4.2.7, and 4.3.0, is_authorized/2 uses is_author...
CVE-2026-66068MEDIUM5.6RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, ?LOG_DEBUG("s...
CVE-2026-66067MEDIUM6RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, The stream open handler calls only chec...
CVE-2026-53979——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-53978——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-53969——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-53968——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-96889HIGH7.8A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate...
CVE-2026-96826HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shazzad Hossain Kh...
CVE-2026-96552LOW3.1A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected eleme...
CVE-2026-96551MEDIUM4.3A vulnerability was determined in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Impacted is an unk...
CVE-2026-96550LOW3.7A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This issue affects the ...
CVE-2026-94183HIGH7.4Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen m...
CVE-2026-87900CRITICAL9.4Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary...
CVE-2026-87899CRITICAL9.4Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root pr...
CVE-2026-87898CRITICAL9.4OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.
CVE-2026-86065HIGH7.5Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe e...
CVE-2026-86064HIGH8.6Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSock...
CVE-2026-85475HIGH7.2A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration ...
CVE-2026-84724MEDIUM6.6An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The ...
CVE-2026-84721MEDIUM6.4A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification...
CVE-2026-84720MEDIUM6.5A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts databa...
CVE-2026-84719CRITICAL9.9A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the dee...
CVE-2026-84718MEDIUM4.3A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now