2026 CVE Vulnerabilities

67,228 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-83603HIGH8.4Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-sta...
CVE-2026-83602MEDIUM6.5Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api...
CVE-2026-83601MEDIUM6.5Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized DIMENS...
CVE-2026-83600MEDIUM6.5Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART ...
CVE-2026-83599HIGH7.5Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates per...
CVE-2026-83598HIGH7.8Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powe...
CVE-2026-76819——Rejected reason: Further research determined the issue results from a dependency.
CVE-2026-76805MEDIUM5.3Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path ...
CVE-2026-76804MEDIUM5.5Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loadi...
CVE-2026-76803MEDIUM5.3Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript...
CVE-2026-76802MEDIUM4.7Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading b...
CVE-2026-56682MEDIUM5.39Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without ...
CVE-2026-13087——Rejected reason: This CVE was reserved in error and duplicates CVE-2026-89530.
CVE-2026-95806HIGH7.7MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point.  The phar...
CVE-2026-95805MEDIUM5.3A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action t...
CVE-2026-95655HIGH8.1Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated use...
CVE-2026-95654HIGH7.4Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization de...
CVE-2026-95653HIGH7.5Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead...
CVE-2026-94640HIGH7.5A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (...
CVE-2026-92706LOW3.4Dark Reader is an accessibility browser extension that makes web pages colors dark. Prior to 4.9.126, a website can caus...
CVE-2026-90462MEDIUM5.4A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `...
CVE-2026-88010MEDIUM6.3Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassword in pkg/middlewar...
CVE-2026-86805MEDIUM6.3A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versio...
CVE-2026-86698LOW2.3Insufficient Session Expiration vulnerability in OAuth token issuance in hexpm hexpm allows a user whose organization me...
CVE-2026-85055HIGH7.1Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.22.0, field-level read permission i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now