2026 CVE Vulnerabilities

67,211 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-71461MEDIUM4.3HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated use...
CVE-2026-71460MEDIUM4.3/api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_...
CVE-2026-71459MEDIUM5JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() ...
CVE-2026-71458MEDIUM5URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. The 403...
CVE-2026-63132CRITICAL9.2OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path...
CVE-2026-63131MEDIUM6OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could ...
CVE-2026-61814HIGH7.5Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON tok...
CVE-2026-61695HIGH7.5Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's S...
CVE-2026-59990HIGH7.5Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nes...
CVE-2026-55632MEDIUM4.3GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompleti...
CVE-2026-55456——Rejected reason: This CVE is a duplicate of another CVE.
CVE-2026-52744MEDIUM5.3GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API a...
CVE-2026-91775HIGH7.4LimeSurvey Community Edition 7.0.14 fails to safely encode attacker-controlled content from a crafted .lss survey file w...
CVE-2026-88840MEDIUM5.3BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.
CVE-2026-88839MEDIUM6.7BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of he...
CVE-2026-88837MEDIUM6.5BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authenticati...
CVE-2026-88835MEDIUM6.1BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap ...
CVE-2026-88831MEDIUM5.3BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the ru...
CVE-2026-86938HIGH7.3A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code ...
CVE-2026-86934CRITICAL9.1An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an exten...
CVE-2026-86930CRITICAL9.1An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted imag...
CVE-2026-86926HIGH7.8A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously...
CVE-2026-86867MEDIUM6.5Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabiliti...
CVE-2026-18944——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-18944. Reason: This candidate is a ...
CVE-2026-96808HIGH7.4In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now