2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41615HIGH7.4Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to...
CVE-2026-7805——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-3258. Reason: This candidate is a r...
CVE-2026-6923LOW3.8A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie...
CVE-2026-45448MEDIUM4.3CWE-601 URL redirection to untrusted site ('open redirect')
CVE-2026-44827HIGH8.8Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execut...
CVE-2026-44516HIGH7.6Valtimo is an open-source business process automation platform. From 12.4.0 to 12.33.0 and 13.26.0, the LoggingRestClien...
CVE-2026-44515LOW2.3Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feed...
CVE-2026-44514MEDIUM6.5Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard exposes WebSocket endpoi...
CVE-2026-44513HIGH8.8Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPip...
CVE-2026-44511HIGH7.4Katalyst Koi is a framework for building Rails admin functionality. Prior to 4.20.0 and 5.6.0, admin session cookies wer...
CVE-2026-44348LOW2.5PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_ha...
CVE-2026-44312MEDIUM5.8css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allo...
CVE-2026-42555CRITICAL9.1Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32...
CVE-2026-20224HIGH8.6A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated,...
CVE-2026-20210MEDIUM5.4A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r...
CVE-2026-20209MEDIUM5.4A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r...
CVE-2026-20182CRITICAL10May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fi...
CVE-2026-44504HIGH8.6Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared ...
CVE-2026-44503HIGH7The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and othe...
CVE-2026-44501HIGH7.1DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserialize...
CVE-2026-42597MEDIUM5.9Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/c...
CVE-2026-42596CRITICAL9.4Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's d...
CVE-2026-42595HIGH8.6Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/f...
CVE-2026-42594HIGH7.5Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine th...
CVE-2026-42593MEDIUM5.3Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoff...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now