2026 CVE Vulnerabilities

64,336 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-46819CRITICAL9.1Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Opera...
CVE-2026-46818HIGH7.4Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi...
CVE-2026-46817CRITICAL9.8Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi...
CVE-2026-46775CRITICAL9.9Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. E...
CVE-2026-45288CRITICAL9.8Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search API...
CVE-2026-44657HIGH7.5Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a vali...
CVE-2026-44655HIGH8.6Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.3.0 to 2.28.1, unescaped Project Name allows an at...
CVE-2026-42400MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)...
CVE-2026-42399MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)...
CVE-2026-42398HIGH7.7Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypas...
CVE-2026-42071HIGH7.2Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2.23.0 to 2.28.1, a missing authorization check in M...
CVE-2026-42070MEDIUM5.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, the mc_issue_update() function in Mantis...
CVE-2026-41897MEDIUM5.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.0.0 to 2.28.1, lack of validation of filter_target...
CVE-2026-35277HIGH8.1Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. E...
CVE-2026-35266HIGH7.9Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. D...
CVE-2026-34311CRITICAL9.8Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component:...
CVE-2026-9039HIGH8.6A configuration weakness in the device’s remote management service allows an authenticated session to be established ove...
CVE-2026-9038HIGH8.6A stack-based buffer overflow vulnerability in the charging controller’s signal-processing logic allows an attacker with...
CVE-2026-9037CRITICAL9.3A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages ...
CVE-2026-49130MEDIUM6.9Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function ...
CVE-2026-49129MEDIUM6.9Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin...
CVE-2026-49128HIGH8.7Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrThrow a...
CVE-2026-49127HIGH8.8Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be f...
CVE-2026-42401MEDIUM5.4Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user...
CVE-2026-33590HIGH8.5Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now