2026 CVE Vulnerabilities

67,237 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-95661MEDIUM5.1MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes v...
CVE-2026-95659MEDIUM4.8MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action. T...
CVE-2026-95658MEDIUM6.9MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list....
CVE-2026-95619HIGH7.7A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in...
CVE-2026-95273MEDIUM4.3A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of ...
CVE-2026-95272LOW3.7A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the f...
CVE-2026-95271HIGH7.3A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_a...
CVE-2026-93616CRITICAL9.8A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary s...
CVE-2026-75791HIGH8.6Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerabi...
CVE-2026-95270LOW3.7A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password o...
CVE-2026-89420HIGH7.1Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obt...
CVE-2026-87119HIGH8.2Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation cre...
CVE-2026-74849CRITICAL9.8Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerabil...
CVE-2026-63279MEDIUM5.4LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an ...
CVE-2026-63278MEDIUM6.7URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information c...
CVE-2026-63276MEDIUM5.4LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and C...
CVE-2026-63275MEDIUM5.4LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hin...
CVE-2026-63274MEDIUM5.4LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of ...
CVE-2026-63273MEDIUM5.4LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The leng...
CVE-2026-63272MEDIUM5.4LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a...
CVE-2026-95623MEDIUM5.6The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the in...
CVE-2026-92882MEDIUM5.3Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15...
CVE-2026-90990MEDIUM5.3Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 a...
CVE-2026-94117HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar –...
CVE-2026-90882HIGH8.7The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-C...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now