2026 CVE Vulnerabilities

67,200 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-77422HIGH7.5JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command ...
CVE-2026-77421MEDIUM6.5JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's...
CVE-2026-77420MEDIUM5.5JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(Str...
CVE-2026-77394HIGH7.6OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-77285LOW2.4OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao Agent's exec rendering mode ...
CVE-2026-76648HIGH8.5CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs n...
CVE-2026-76089HIGH7.7Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-rese...
CVE-2026-76087HIGH8.2Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's anonymous formie/submissions/submi...
CVE-2026-76086HIGH8.5Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings ...
CVE-2026-75131HIGH7.8NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains a privilege escalation vulnerability that allows local use...
CVE-2026-71465LOW3.1RunAdHocCommand.build_args() appends limit as bare positional (args.append(limit)) instead of using ...
CVE-2026-71464LOW3.1LaunchConfigurationBaseSerializer.scm_branch has no validate_scm_branch() leading-dash check, unlike ...
CVE-2026-71463LOW2.7Notification template Jinja AST whitelist only inspects static Getattr nodes. Dynamic subscripts (job['job...
CVE-2026-71462MEDIUM4.1StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. ...
CVE-2026-71461MEDIUM4.3HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated use...
CVE-2026-71460MEDIUM4.3/api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_...
CVE-2026-71459MEDIUM5JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() ...
CVE-2026-71458MEDIUM5URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. The 403...
CVE-2026-63132CRITICAL9.2OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path...
CVE-2026-63131MEDIUM6OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could ...
CVE-2026-61814HIGH7.5Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON tok...
CVE-2026-61695HIGH7.5Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's S...
CVE-2026-59990HIGH7.5Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nes...
CVE-2026-55632MEDIUM4.3GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompleti...
CVE-2026-55456——Rejected reason: This CVE is a duplicate of another CVE.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now