2026 CVE Vulnerabilities

64,659 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40597HIGH7.6Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS ...
CVE-2026-40596HIGH7.2Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.11.0 through 2.28.1 allow any authenticated us...
CVE-2026-40295MEDIUM6.1Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module...
CVE-2026-39824LOW3.3NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum siz...
CVE-2026-9291HIGH7.5Insecure deserialization in the job results processing component in Amazon Braket SDK before 1.117.0 might allow a remot...
CVE-2026-6406HIGH8.8The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When EC...
CVE-2026-48700CRITICAL9.3An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI...
CVE-2026-40172HIGH8.1authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PAT...
CVE-2026-40166HIGH7.1authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authent...
CVE-2026-39970HIGH8.5TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerability in the app.type...
CVE-2026-39969MEDIUM6.5TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/works...
CVE-2026-39968HIGH7.1TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via ...
CVE-2026-39967LOW3.1TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult query does not filter r...
CVE-2026-39966MEDIUM6.5TypeBot is a chatbot builder tool. In versions 3.15.2, the getLinkedTypebots API endpoint returns full bot definitions t...
CVE-2026-46727HIGH8.1An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getadd...
CVE-2026-42627MEDIUM6.2In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a craft...
CVE-2026-39965HIGH7.7TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Reques...
CVE-2026-39964MEDIUM5.4TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor t...
CVE-2026-9255HIGH8.4Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to ex...
CVE-2026-42626MEDIUM5.9HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetD...
CVE-2026-37470HIGH7.3An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login p...
CVE-2026-36228HIGH7.3Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execu...
CVE-2026-36227MEDIUM6.5Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and e...
CVE-2026-36226MEDIUM6.1Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensit...
CVE-2026-34207HIGH7.6TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks valida...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now