2026 CVE Vulnerabilities

64,617 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8850HIGH7.5IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload.
CVE-2026-48905MEDIUM6.1Lack of input filtering leads to an XSS vector in the HTML filter code.
CVE-2026-48904CRITICAL9.8An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
CVE-2026-48903MEDIUM6.1Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
CVE-2026-48902CRITICAL9.8The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't e...
CVE-2026-48901HIGH7.5The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
CVE-2026-48900MEDIUM4.3An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
CVE-2026-48899CRITICAL9.8An improper access check allows privilege escalation through the com_users batch task.
CVE-2026-48898CRITICAL9.8An improper access check allows privilege escalation through the com_users batch task.
CVE-2026-48897HIGH7.5Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-48896HIGH7.5Insufficient state checks lead to a vector that allows to bypass 2FA checks.
CVE-2026-48864HIGH7.8A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed...
CVE-2026-48697HIGH7.4FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_w...
CVE-2026-48693MEDIUM5.5FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via predictable file paths in /tmp. T...
CVE-2026-48691CRITICAL9.8FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp...
CVE-2026-48690HIGH7.1FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer alloc...
CVE-2026-48126HIGH8.2Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --let...
CVE-2026-48091——Rejected reason: Further research determined the issue is not a vulnerability.
CVE-2026-47728MEDIUM4.3Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug files by debug ID wi...
CVE-2026-47716LOW3.1Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, In affected versions, the issue list view authorizes acces...
CVE-2026-47715LOW3.1Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a direct event identifier...
CVE-2026-46431MEDIUM4.3Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server's Access-Control-Allow-Orig...
CVE-2026-46430MEDIUM4.3Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, the SSE event server bound to 0.0.0.0:5553 on Li...
CVE-2026-45836MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_...
CVE-2026-45835MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now