2026 CVE Vulnerabilities

67,213 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93349HIGH8.8Frictionless before 5.19.1 contains an OS command injection vulnerability in the explore console command that allows an ...
CVE-2026-88832HIGH7.3BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow wh...
CVE-2026-88830HIGH7.5A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow ...
CVE-2026-85724CRITICAL9.6Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, Authorizations...
CVE-2026-6669MEDIUM5.9Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in Pg...
CVE-2026-6668HIGH7.5Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker...
CVE-2026-19888HIGH7.5Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows ...
CVE-2026-96675LOW3.3alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate spar...
CVE-2026-96674MEDIUM4.4alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowin...
CVE-2026-96673HIGH7.5Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated ...
CVE-2026-96672MEDIUM6.4Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values refere...
CVE-2026-93769HIGH7.2HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegate...
CVE-2026-79310HIGH8.5webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into execut...
CVE-2026-79306MEDIUM6.5CyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through the /filemanager/contro...
CVE-2026-79304MEDIUM6.5CyberPanel 1.9.1 contains a path traversal vulnerability in the readFileContents method of the /filemanager/controller e...
CVE-2026-6327MEDIUM4.3IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutra...
CVE-2026-4921LOW2.7IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a detailed tec...
CVE-2026-3626MEDIUM5.3IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical ...
CVE-2026-19267MEDIUM6.2IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rul...
CVE-2026-19179HIGH8.2IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database querie...
CVE-2026-19087MEDIUM4.4IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalatio...
CVE-2026-18875HIGH7.3IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook ...
CVE-2026-18872CRITICAL9.3IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in th...
CVE-2026-18505MEDIUM5.4IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter...
CVE-2026-18490HIGH8.8IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now