2026 CVE Vulnerabilities

63,709 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44794MEDIUM5.4Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-o...
CVE-2026-43898CRITICAL10SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing...
CVE-2026-34126HIGH7.5TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth...
CVE-2026-9098CRITICAL9.1In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLRe...
CVE-2026-9097CRITICAL9.8Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExcha...
CVE-2026-9096HIGH7.5Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-val...
CVE-2026-9095HIGH8.1Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlRespon...
CVE-2026-9094CRITICAL9.8Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExc...
CVE-2026-9093CRITICAL9.8In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestrict...
CVE-2026-9092CRITICAL9.1Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account ...
CVE-2026-9091MEDIUM5.3Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass c...
CVE-2026-9090CRITICAL9.1Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplyi...
CVE-2026-8697HIGH8.8Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service all...
CVE-2026-6720HIGH7.2When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded ...
CVE-2026-47676MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() stri...
CVE-2026-47675MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() ...
CVE-2026-47674MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restricti...
CVE-2026-47673MEDIUM6.5Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk ...
CVE-2026-45292MEDIUM5.3opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing tel...
CVE-2026-45261CRITICAL9.3GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execut...
CVE-2026-45078MEDIUM5.5Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synaps...
CVE-2026-45076LOW2.7Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers ...
CVE-2026-44543HIGH8.7Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.3...
CVE-2026-44477CRITICAL9.9CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and ...
CVE-2026-44466HIGH8.6Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expans...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now