2026 CVE Vulnerabilities

67,222 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-95814HIGH8.1Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries,...
CVE-2026-95813MEDIUM6.1e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails url_for in PaginatorComponent and co...
CVE-2026-95812MEDIUM6.1ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper functi...
CVE-2026-94450HIGH7.5Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated ...
CVE-2026-91018HIGH8.8lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or ...
CVE-2026-89019——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-88020MEDIUM6.1Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability ...
CVE-2026-77987CRITICAL9.8A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. Th...
CVE-2026-77912MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticat...
CVE-2026-77426HIGH7.1Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five authorization...
CVE-2026-77425MEDIUM4.3Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:fea...
CVE-2026-76910MEDIUM5.3Unleash is an open-source feature management platform. Prior to 8.0.3, cloneFeatureToggle and POST /api/admin/projects/:...
CVE-2026-76909LOW2.1Unleash is an open-source feature management platform. Prior to 8.0.3, the change-request approval email template at src...
CVE-2026-75101MEDIUM6.5An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of ...
CVE-2026-67615HIGH8.8openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allows any authenticated ...
CVE-2026-62364LOW2.3wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration fr...
CVE-2026-94574HIGH7.8A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a har...
CVE-2026-89282CRITICAL9.1The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissio...
CVE-2026-89281HIGH8.4The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability...
CVE-2026-88624CRITICAL9.1Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recu...
CVE-2026-88419HIGH8.8An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=...
CVE-2026-88418HIGH8.8CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-c...
CVE-2026-88416——MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom model/form import feature.
CVE-2026-88350MEDIUM6.2An integer overflow vulnerability exists in MPack 1.1.1 in mpack_node_cstr_alloc() and mpack_node_utf8_cstr_alloc().
CVE-2026-88345HIGH7.5An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers sche...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now