2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8043CRITICAL9.6External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read...
CVE-2026-7432HIGH7A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges...
CVE-2026-7431MEDIUM4.4An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local a...
CVE-2026-6866HIGH7.5CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclo...
CVE-2026-5061MEDIUM4.7The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper tha...
CVE-2026-43983HIGH8.1Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, Th...
CVE-2026-43939HIGH7.3YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature acc...
CVE-2026-43938HIGH8.1YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNE...
CVE-2026-43937HIGH8.8YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects...
CVE-2026-42260HIGH8.2Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to ...
CVE-2026-32687HIGH7.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgr...
CVE-2026-8391MEDIUM5.3Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Fir...
CVE-2026-8390HIGH7.3Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.
CVE-2026-8389HIGH8.8JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.
CVE-2026-8388MEDIUM6.5Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3, ...
CVE-2026-6865HIGH7.1CWE-22: Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) vulnerability that could cause un...
CVE-2026-45091CRITICAL9.1sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterp...
CVE-2026-43930MEDIUM5.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 ...
CVE-2026-43916HIGH8.7pam_authnft is a PAM session module binding nftables firewall rules to authenticated sessions via cgroupv2 inodes. Prior...
CVE-2026-42006MEDIUM4.3An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomple...
CVE-2026-40638MEDIUM6.7Dell PowerScale InsightIQ, versions 5.0.0 through 6.2.0, contains an execution with unnecessary privileges vulnerability...
CVE-2026-40020MEDIUM4.3Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_all...
CVE-2026-40016MEDIUM6.5Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits ...
CVE-2026-35071HIGH8.2Dell PowerScale InsightIQ, versions 6.0.0 through 6.2.0, contains an improper neutralization of special elements used in...
CVE-2026-33603MEDIUM5.3Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now