2026 CVE Vulnerabilities

67,214 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-62998MEDIUM4.3REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_list::getSortColumn() in redaxo/src/core/lib/list....
CVE-2026-61834MEDIUM4.3scim-patch is a library for applying SCIM patch operations. Prior to 0.9.2, navigate() reads inherited properties and as...
CVE-2026-61413MEDIUM6.8Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Managemen...
CVE-2026-55610HIGH8.7InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and...
CVE-2026-96560CRITICAL9.8LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_t...
CVE-2026-96559——Rejected reason: This ID was for testing
CVE-2026-96512HIGH7.8A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps th...
CVE-2026-86708CRITICAL10ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud servi...
CVE-2026-86683HIGH8.1ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy s...
CVE-2026-86681HIGH7.6ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue t...
CVE-2026-86679HIGH7.1ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue t...
CVE-2026-86678HIGH8.8ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administ...
CVE-2026-86677HIGH8.8ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized S...
CVE-2026-59167CRITICAL10SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the...
CVE-2026-18179MEDIUM6.5IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions...
CVE-2026-18177HIGH7.1IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payme...
CVE-2026-12974HIGH7.9A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW). This issue affects Forcepoint Secu...
CVE-2026-95676HIGH7.4A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authenticat...
CVE-2026-86247HIGH7.4Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirement...
CVE-2026-86246CRITICAL9.1Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by ...
CVE-2026-86243HIGH7.5Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a Do...
CVE-2026-84091MEDIUM5.3The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a...
CVE-2026-77112MEDIUM6.5Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc. Weoll allows Server S...
CVE-2026-76980HIGH7.4ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vul...
CVE-2026-76979HIGH7.7ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now