2026 CVE Vulnerabilities

64,889 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33448LOW3.3CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to 14....
CVE-2026-33447CRITICAL9.8CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers...
CVE-2026-33446CRITICAL9.8CVE-2026-33446 is a buffer overflow in the authentication sub-system of the Secure Access client prior to 14.50. Attack...
CVE-2026-7461HIGH7.5Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amaz...
CVE-2026-40904HIGH8.1Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-40603MEDIUM6.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-40601HIGH7.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-40600HIGH8.1Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-40595HIGH7.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-35514MEDIUM6.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-32148MEDIUM5.9Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency...
CVE-2026-3833HIGH7.4A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstra...
CVE-2026-3832LOW3.7A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online ...
CVE-2026-36766MEDIUM5.4Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer ...
CVE-2026-36765HIGH8.8An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticat...
CVE-2026-36763MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 al...
CVE-2026-36762HIGH8.8An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers ...
CVE-2026-36761MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers...
CVE-2026-33845CRITICAL9.1A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an i...
CVE-2026-36767CRITICAL10A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary f...
CVE-2026-36764MEDIUM5A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows aut...
CVE-2026-36760CRITICAL9.6An issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with ...
CVE-2026-36757MEDIUM4.3A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authentica...
CVE-2026-5174HIGH8.8Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue ...
CVE-2026-4670CRITICAL9.8Authentication bypass by primary weakness vulnerability in Progress Software MOVEit Automation allows Authentication Byp...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now