2026 CVE Vulnerabilities

67,214 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-18490HIGH8.8IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via ...
CVE-2026-18185HIGH7.3IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive informati...
CVE-2026-18184HIGH7.4IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive informati...
CVE-2026-18181HIGH8.1IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and ...
CVE-2026-18180MEDIUM6.5IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensi...
CVE-2026-96611MEDIUM6.9FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values f...
CVE-2026-96609HIGH7.1Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console lo...
CVE-2026-96600MEDIUM5.5Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate requ...
CVE-2026-96599MEDIUM5.9Isotope eCommerce through 2.9.10 derives order identifiers from uniqid() instead of a cryptographically secure source, a...
CVE-2026-96276MEDIUM6.5If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak ...
CVE-2026-96275HIGH8.8A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host f...
CVE-2026-92419MEDIUM5.3WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in the /api/vacations/{path} endpoint. The selectedP...
CVE-2026-92164MEDIUM6.5Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.6.0, HTTPSes...
CVE-2026-88974MEDIUM5.4WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjec...
CVE-2026-73858MEDIUM5.3Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted...
CVE-2026-73591HIGH7.5Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Infor...
CVE-2026-73589MEDIUM6.3Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak ...
CVE-2026-73588HIGH7.4Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Cr...
CVE-2026-73587MEDIUM6.8Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validat...
CVE-2026-73586MEDIUM6.4Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expirat...
CVE-2026-71178LOW3.7Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Pat...
CVE-2026-71177MEDIUM5.4Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rend...
CVE-2026-63002MEDIUM4.8REDAXO is a PHP-based content management system. Prior to 5.21.2, redaxo/src/addons/mediapool/pages/sync.php inserts fil...
CVE-2026-63001MEDIUM4.8REDAXO is a PHP-based content management system. Prior to 5.21.2, the mediaIsInUse() handler in redaxo/src/addons/media_...
CVE-2026-63000MEDIUM6.4REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_api_install_package_update in redaxo/src/addons/in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now