2026 CVE Vulnerabilities

42,999 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-66382MEDIUM4.3An authenticated user may write files outside the intended Artifactory work directory under specific conditions.
CVE-2026-66381MEDIUM5.3A repository reader with cache-deploy permission may access content outside a configured upstream path under specific co...
CVE-2026-66380MEDIUM4.3An authenticated user without repository read permission may access private OCI referrer metadata under specific conditi...
CVE-2026-66379MEDIUM4.3An authenticated user may view private Puppet module metadata without repository read access.
CVE-2026-66378MEDIUM4.3An authenticated user without repository read permission may access private NuGet metadata under specific conditions.
CVE-2026-66377MEDIUM5.3An unauthenticated user may access restricted repository information under specific conditions.
CVE-2026-66376MEDIUM4.2Credentials for a deleted user may remain valid for a short period under specific conditions.
CVE-2026-66375HIGH8.1A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific...
CVE-2026-50561CRITICAL9.4Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version ...
CVE-2026-49349MEDIUM6.8regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvert...
CVE-2026-49262LOW3In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is ...
CVE-2026-47234MEDIUM4.4Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::se...
CVE-2026-47233MEDIUM6.5Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `...
CVE-2026-18171MEDIUM5.7Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the und...
CVE-2026-14479MEDIUM5.5A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation ...
CVE-2026-14478HIGH7.8A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to in...
CVE-2026-67285CRITICAL9.2Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An u...
CVE-2026-47232MEDIUM4.3Admidio is an open-source user management solution. Prior to version 5.0.10, the sensitive `mode=export` action in `modu...
CVE-2026-47231HIGH8.1Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-c...
CVE-2026-47230MEDIUM6.5Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` mode `file_re...
CVE-2026-47229MEDIUM5.4Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm...
CVE-2026-47228MEDIUM5.2Admidio is an open-source user management solution. `modules/registration.php` mode `send_login` regenerates a random pa...
CVE-2026-47227MEDIUM6.5Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (...
CVE-2026-16999MEDIUM6.3Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows S...
CVE-2026-71408MEDIUM5.3A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now