2026 CVE Vulnerabilities

44,991 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-11889HIGH7.1SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation at...
CVE-2026-63397HIGH7.1remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed t...
CVE-2026-62963HIGH8.7Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.4, Centrifugo unidirectional WebSocket tr...
CVE-2026-62309HIGH7.5CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when...
CVE-2026-62290HIGH7.3cert-manager adds certificates and certificate issuers as resource types in Kubernetes clusters, and simplifies the proc...
CVE-2026-61389HIGH7.3An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupt...
CVE-2026-60063HIGH7.3An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corrupt...
CVE-2026-55629HIGH8.7Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cg...
CVE-2026-49998HIGH8.2Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verif...
CVE-2026-44982HIGH7.2CrowdSec offers crowdsourced protection against malicious IPs. From 1.5.0 until 1.7.8, pkg/appsec/request.go NewParsedRe...
CVE-2026-44981HIGH8.2CrowdSec offers crowdsourced protection against malicious IPs. From 1.7.0 until 1.7.8, the LAPI router used gin-contrib/...
CVE-2026-15352HIGH8.2A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the a...
CVE-2026-46513HIGH7.4Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by T...
CVE-2026-46353HIGH8.1BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a...
CVE-2026-46351HIGH8.1BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values wit...
CVE-2026-46687HIGH7.7Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-t...
CVE-2026-46686HIGH8.5Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user search module's keyword p...
CVE-2026-46336HIGH7.1Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on ...
CVE-2026-9046HIGH7.3A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications...
CVE-2026-63088HIGH8.6stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-...
CVE-2026-63086HIGH8.6text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat...
CVE-2026-63085HIGH8.8Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticate...
CVE-2026-45576HIGH7.5zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores at...
CVE-2026-45367HIGH7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7,...
CVE-2026-45325HIGH8.2Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now