2026 CVE Vulnerabilities

46,928 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-18860HIGH8.7Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can cr...
CVE-2026-18636MEDIUM6.8The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users fr...
CVE-2026-18635HIGH7.2Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able ...
CVE-2026-18129HIGH8.1Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a ...
CVE-2026-18127HIGH7.7External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authentica...
CVE-2026-18125HIGH7.5An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated at...
CVE-2026-17535MEDIUM6.2Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by...
CVE-2026-17061CRITICAL10A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2...
CVE-2026-73210MEDIUM5.1A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup o...
CVE-2026-51584CRITICAL9.8An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the S...
CVE-2026-51583HIGH8.5An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF...
CVE-2026-48056CRITICAL10Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 impro...
CVE-2026-48046CRITICAL9.3Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contai...
CVE-2026-46670CRITICAL9.8YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-imp...
CVE-2026-19539HIGH8.6Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5...
CVE-2026-19434MEDIUM5.1Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute ar...
CVE-2026-72785CRITICAL9.3Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only ...
CVE-2026-72784MEDIUM6.9Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulne...
CVE-2026-72783MEDIUM6.9Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakne...
CVE-2026-72782HIGH7.1Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secre...
CVE-2026-72781HIGH8.8Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerabili...
CVE-2026-72780HIGH7.1Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey ...
CVE-2026-72779HIGH8.7Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create()...
CVE-2026-72778HIGH8.8Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code ex...
CVE-2026-72775MEDIUM5.8n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interp...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now