2026 CVE Vulnerabilities

44,976 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-9171HIGH7.5IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused ...
CVE-2026-58195HIGH8.8Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone...
CVE-2026-53712HIGH8.2SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security L...
CVE-2026-52746HIGH7.5JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious non-matching inputs to the $toM...
CVE-2026-49835HIGH7.5Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middle...
CVE-2026-45309HIGH7.5AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to...
CVE-2026-45162HIGH8Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore loc...
CVE-2026-9762HIGH7.8IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under u...
CVE-2026-50273HIGH7.5Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing librarie...
CVE-2026-9588HIGH7A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicem...
CVE-2026-9587HIGH7.1An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file ...
CVE-2026-9585HIGH8.6An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8....
CVE-2026-63307HIGH7.1Chat2DB before 5.3.0 contains an insecure direct object reference vulnerability in the GET /api/connection/datasource/{i...
CVE-2026-63101HIGH8.7Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers t...
CVE-2026-57860HIGH7.8ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes the MCP servers defined i...
CVE-2026-49212HIGH7.5Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\Liv...
CVE-2026-49211HIGH7.5Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, Symfony\UX\Autocomplete\Doctrine\En...
CVE-2026-12691HIGH7.5Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authenticat...
CVE-2026-63100HIGH7.1Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role u...
CVE-2026-63099HIGH7.1TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints t...
CVE-2026-63095HIGH7.1Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any...
CVE-2026-60025HIGH8.8Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking p...
CVE-2026-58148HIGH8.7Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension...
CVE-2026-15343HIGH8.6A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code executio...
CVE-2026-14871HIGH7.1osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Obje...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now