2026 CVE Vulnerabilities

64,474 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44972MEDIUM5GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled f...
CVE-2026-44971HIGH8.2GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scannin...
CVE-2026-44902HIGH7.5opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any N...
CVE-2026-44839MEDIUM4.8RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1...
CVE-2026-44838HIGH8.1RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level ...
CVE-2026-44830HIGH8.7Nocturne Memory is a lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Prior to 2.4.1, when ...
CVE-2026-42280HIGH7.1Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.j...
CVE-2026-42184HIGH8.8Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_loc...
CVE-2026-37713HIGH7.3An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary ...
CVE-2026-37712HIGH7.3An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary ...
CVE-2026-37711HIGH7.3An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary ...
CVE-2026-31266HIGH7.3Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate...
CVE-2026-30498MEDIUM6.3A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delete.php endpoint of Jason2605 AdminPanel 4.0.
CVE-2026-1248MEDIUM4.3IBM Business Automation Workflow containers and traditional may leak information about its database structure in error m...
CVE-2026-9704HIGH8.8A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an ove...
CVE-2026-9617HIGH8.8PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and p...
CVE-2026-9035MEDIUM6.5IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 t...
CVE-2026-8405MEDIUM6.5IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention...
CVE-2026-8180HIGH7.5IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 t...
CVE-2026-8179HIGH8.8IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 t...
CVE-2026-8175CRITICAL9.8IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 t...
CVE-2026-7876CRITICAL9.1IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19 is affected by an authentication bypass vulnerability. A transfer client m...
CVE-2026-7528HIGH7.5IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption.
CVE-2026-7524CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links duri...
CVE-2026-7365HIGH7.8IBM Operations Analytics - Log Analysis  and IBM SmartCloud Analytics - Log Analysis uses default passwords default pass...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now