2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44011HIGH8.6Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an inp...
CVE-2026-44010HIGH7.1Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element res...
CVE-2026-35504MEDIUM5.5PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communicati...
CVE-2026-8052MEDIUM6HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as ...
CVE-2026-7474HIGH8.8HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path t...
CVE-2026-6959MEDIUM6HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host a...
CVE-2026-45185CRITICAL9.8Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing p...
CVE-2026-44874MEDIUM4.9A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remo...
CVE-2026-44873MEDIUM5.4A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their a...
CVE-2026-44872HIGH7.2A command injection vulnerability exists in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Su...
CVE-2026-44870HIGH8.8Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS...
CVE-2026-44869HIGH8.8Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc...
CVE-2026-44868HIGH8.8Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc...
CVE-2026-44867HIGH8.8Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc...
CVE-2026-44866HIGH8.8Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc...
CVE-2026-44865HIGH7.2Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Suc...
CVE-2026-44864HIGH7.2SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com...
CVE-2026-44863HIGH7.2SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com...
CVE-2026-44862HIGH7.2SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com...
CVE-2026-44861HIGH7.2SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com...
CVE-2026-44860HIGH7.2SQL injection vulnerabilities exist in several underlying service components accessible through the AOS-8 and AOS-10 com...
CVE-2026-44859HIGH7.2Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through t...
CVE-2026-44858HIGH7.2Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through t...
CVE-2026-44857HIGH7.2Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through t...
CVE-2026-44856HIGH7.2Stack-based buffer overflow vulnerabilities exist in several underlying management service components accessed through t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now