2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44368MEDIUM6.9PyQuorum is a cryptographic library for secret sharing and key management. Prior to 0.2.1, the mul_mod function implemen...
CVE-2026-42602HIGH8.1azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in...
CVE-2026-42561HIGH7.5Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service v...
CVE-2026-42304HIGH7.5Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.n...
CVE-2026-39428MEDIUM4.8CubeCart is an ecommerce software solution. Prior to 6.6.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in ...
CVE-2026-39358HIGH7.2CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities...
CVE-2026-21821HIGH8.3The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1...
CVE-2026-44364CRITICAL9.3MISP modules are autonomous modules that can be used to extend MISP for new services. In 3.0.7 and earlier, a Cross-Site...
CVE-2026-44363MEDIUM5.8MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote r...
CVE-2026-44351CRITICAL9.1fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.4, a critical authentication-bypass vulnerabili...
CVE-2026-42552HIGH7.5Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the default error handler Engine::_error() writes the ...
CVE-2026-42551HIGH7.5Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Request::getMethod() unconditionally honors the X-HTTP...
CVE-2026-42550HIGH8.8Flight is an extensible micro-framework for PHP. Prior to 3.18.1, SimplePdo::insert(), SimplePdo::update(), and SimplePd...
CVE-2026-42549MEDIUM4.4Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the make:controller CLI command calls mkdir(..., recur...
CVE-2026-42548HIGH8.6Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Flight::jsonp() concatenates the ?jsonp= query paramet...
CVE-2026-33381HIGH8.1When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few ...
CVE-2026-33380MEDIUM6.5A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's fi...
CVE-2026-33378MEDIUM6.5Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the s...
CVE-2026-33377HIGH7.1An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have wr...
CVE-2026-33376HIGH7.4When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask expl...
CVE-2026-28383MEDIUM6.5A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request b...
CVE-2026-28380MEDIUM6.5Any Editor could delete any snapshot, even if they have no access to read or write them.
CVE-2026-28379MEDIUM6.5A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concur...
CVE-2026-28376MEDIUM6.5The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming req...
CVE-2026-28374MEDIUM4.3Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now