2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-46446HIGH7.1SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This i...
CVE-2026-46445HIGH7.1SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection.
CVE-2026-46419HIGH7.5Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value i...
CVE-2026-44919MEDIUM6.5In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can oc...
CVE-2026-41281MEDIUM6.3Android App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext Transmission of Sensitive Information (CW...
CVE-2026-8500CRITICAL9.8Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing ht...
CVE-2026-32991HIGH7.1Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner ac...
CVE-2026-29206HIGH8.1Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the roo...
CVE-2026-45158CRITICAL9.1OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP...
CVE-2026-44478HIGH7.5hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the una...
CVE-2026-44471HIGH7.8gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, wh...
CVE-2026-44448MEDIUM6.5ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints fa...
CVE-2026-44447HIGH7.5ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to ...
CVE-2026-44446HIGH7.5ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were ...
CVE-2026-44445MEDIUM6.5ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restrict...
CVE-2026-44442CRITICAL9.9ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforc...
CVE-2026-44441MEDIUM4.3ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user cou...
CVE-2026-44440MEDIUM5.7ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitati...
CVE-2026-44439HIGH7.5PlaywrightCapture is a simple replacement for splash using playwright. Prior to 1.39.6, PlaywrightCapture did not suffic...
CVE-2026-44437MEDIUM6.1The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25,...
CVE-2026-44426MEDIUM6.5ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/namespaces/:tenant returns the full namespace object — ...
CVE-2026-44425MEDIUM5.4ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in ...
CVE-2026-44424MEDIUM6.5ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/devices/:uid returns the full device object whenever th...
CVE-2026-44423MEDIUM6.5ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/sessions/:uid returns the full session object for any a...
CVE-2026-44369HIGH8.5CVAT is an open source interactive video and image annotation tool for computer vision. From 2.5.0 to 2.63.0, an attacke...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now