2026 CVE Vulnerabilities

67,213 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-18944——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-18944. Reason: This candidate is a ...
CVE-2026-96808HIGH7.4In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivi...
CVE-2026-96807MEDIUM4In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regener...
CVE-2026-96804HIGH8.8MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security contr...
CVE-2026-96775HIGH8.8MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when...
CVE-2026-96759CRITICAL9.8orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator opt...
CVE-2026-96758CRITICAL9.8orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape...
CVE-2026-96757CRITICAL9.8orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string li...
CVE-2026-96756HIGH8.1orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to e...
CVE-2026-96755CRITICAL9.8orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts...
CVE-2026-96754CRITICAL9.8orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape Op...
CVE-2026-96656HIGH7.2Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The pr...
CVE-2026-96655MEDIUM4.3Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses v...
CVE-2026-96654MEDIUM6.5Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an atta...
CVE-2026-96652MEDIUM4.3Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can i...
CVE-2026-96651MEDIUM6.5Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, a...
CVE-2026-96514HIGH7.3A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogi...
CVE-2026-96513HIGH7.3A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the fil...
CVE-2026-95848CRITICAL9.1Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class canno...
CVE-2026-95847HIGH7.5Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as q...
CVE-2026-95846HIGH7.5Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will messa...
CVE-2026-95845HIGH7.5Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending pe...
CVE-2026-95844HIGH7.5Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names and topic ...
CVE-2026-95843HIGH7.5Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter th...
CVE-2026-95842HIGH7.5Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEventLoop.run catches only InterruptedException, and...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now