2026 CVE Vulnerabilities

64,617 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48962HIGH7.3IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled ou...
CVE-2026-48961HIGH7.3IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine...
CVE-2026-48959HIGH7.5IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastFo...
CVE-2026-2255MEDIUM4.3Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, e...
CVE-2026-2254MEDIUM6.3Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, d...
CVE-2026-2253HIGH7.7Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, d...
CVE-2026-9632HIGH8.8A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of th...
CVE-2026-9631HIGH8.8A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the functi...
CVE-2026-9628HIGH8.8A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /gofo...
CVE-2026-9627HIGH8.8A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file...
CVE-2026-9609MEDIUM4.7A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The ...
CVE-2026-9608LOW2.4A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /T...
CVE-2026-9207HIGH8.8Tanium addressed an unauthorized code execution vulnerability in Connect.
CVE-2026-9156HIGH7.5Tanium addressed a denial of service vulnerability in Tanium Server.
CVE-2026-7493MEDIUM5.3The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to den...
CVE-2026-6565MEDIUM6.4The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulner...
CVE-2026-49017MEDIUM6.5In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-ch...
CVE-2026-49014HIGH7.8In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buf...
CVE-2026-9607MEDIUM6.3A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of ...
CVE-2026-9606HIGH7.3A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the fil...
CVE-2026-9605HIGH7.3A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c ...
CVE-2026-9312HIGH8.2A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenti...
CVE-2026-8606MEDIUM5.9A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker t...
CVE-2026-9604MEDIUM4.3A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragMod...
CVE-2026-8680——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now