2026 CVE Vulnerabilities

64,474 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49047MEDIUM4.3Missing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Securit...
CVE-2026-49046HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Dupli...
CVE-2026-49045MEDIUM4.3Missing Authorization vulnerability in WP Media Adminimize allows Exploiting Incorrectly Configured Access Control Secur...
CVE-2026-49044MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Kruit Advan...
CVE-2026-48973MEDIUM4.3Missing Authorization vulnerability in Benbodhi SVG Support allows Exploiting Incorrectly Configured Access Control Secu...
CVE-2026-48927MEDIUM5.5Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting...
CVE-2026-48926MEDIUM4.3Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allow...
CVE-2026-48925MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integration Plugin 0.7.3 and earlier allows attacker...
CVE-2026-48924MEDIUM4.3Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to pe...
CVE-2026-48923MEDIUM4.3Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation...
CVE-2026-48922HIGH7.5Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip...
CVE-2026-48921HIGH7.5Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared l...
CVE-2026-48920HIGH8.8Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by set...
CVE-2026-48919MEDIUM6.6Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.
CVE-2026-48918MEDIUM6.6Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.
CVE-2026-48917MEDIUM6.6Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.
CVE-2026-48916MEDIUM6.6Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.
CVE-2026-48545MEDIUM6.8Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Spa...
CVE-2026-48544HIGH8.7Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in the ElementLibrary.get_resource() metho...
CVE-2026-47119MEDIUM6.1Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arb...
CVE-2026-47118HIGH7.1Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arb...
CVE-2026-45571MEDIUM5.4go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validat...
CVE-2026-45570CRITICAL9.6go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH t...
CVE-2026-45022HIGH7.5go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may par...
CVE-2026-44988HIGH8.8LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and earlier, LibVNCClient's Tight encoding ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now