2026 CVE Vulnerabilities

44,969 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-47871HIGH8.8VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, au...
CVE-2026-47870HIGH7.1VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network acce...
CVE-2026-47869HIGH8.7VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network acc...
CVE-2026-47868HIGH7.8VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be ...
CVE-2026-47867HIGH8.7VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be abl...
CVE-2026-47866HIGH8.3VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a l...
CVE-2026-16084HIGH7.3A weakness has been identified in Sipeed PicoClaw up to 0.2.9. This impacts the function web_fetch of the file pkg/tools...
CVE-2026-56741HIGH7.5JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote...
CVE-2026-56740HIGH7.5JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote...
CVE-2026-56171HIGH7.5Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disc...
CVE-2026-49485HIGH7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 ...
CVE-2026-54498HIGH8.7view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4...
CVE-2026-54466HIGH7.5websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions ...
CVE-2026-53727HIGH8.9css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb,...
CVE-2026-52584HIGH7.1Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via ...
CVE-2026-52203HIGH7.5An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter.
CVE-2026-50274HIGH7.5Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monit...
CVE-2026-50272HIGH7.5dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/bagga...
CVE-2026-50271HIGH7.5Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C bagga...
CVE-2026-45784HIGH7.1rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::ciph...
CVE-2026-44891HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2...
CVE-2026-13445HIGH8.1IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read an...
CVE-2026-8056HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API...
CVE-2026-7872HIGH8.1IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing...
CVE-2026-7755HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcemen...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now