2026 CVE Vulnerabilities

44,973 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-7755HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcemen...
CVE-2026-7667HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacke...
CVE-2026-54465HIGH7.5websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to im...
CVE-2026-54463HIGH7.5websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket pro...
CVE-2026-51833HIGH7.5Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can ...
CVE-2026-50289HIGH8.8systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is v...
CVE-2026-50197HIGH7.8Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent...
CVE-2026-50163HIGH7.1oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 vali...
CVE-2026-50151HIGH7.5oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completeP...
CVE-2026-4942HIGH7.5IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Tran...
CVE-2026-49852HIGH8.7joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar...
CVE-2026-49834HIGH7.5sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransp...
CVE-2026-49284HIGH7.1SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7 and 2.5.2, SimpleSA...
CVE-2026-48373HIGH7.8Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution i...
CVE-2026-45799HIGH7.5Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArra...
CVE-2026-45704HIGH7.1Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses i...
CVE-2026-45260HIGH8.1Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV ass...
CVE-2026-44974HIGH7.7@hapi/content provided HTTP Content-* headers parsing. Prior to 6.0.2, Content.disposition() retained the last occurrenc...
CVE-2026-44739HIGH8.7Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigActi...
CVE-2026-16118HIGH7.1A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the ...
CVE-2026-15322HIGH7.5IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the ...
CVE-2026-14979HIGH7.5IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ...
CVE-2026-14971HIGH7IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attac...
CVE-2026-14499HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elev...
CVE-2026-9171HIGH7.5IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now