2026 CVE Vulnerabilities

64,952 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33819CRITICAL9.8Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
CVE-2026-33102CRITICAL9.3Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privilege...
CVE-2026-32210HIGH7.5Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofin...
CVE-2026-32172HIGH8Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.
CVE-2026-2708MEDIUM5.3A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_commo...
CVE-2026-26210CRITICAL9.8KTransformers through 0.5.3 contains an unsafe deserialization vulnerability in the balance_serve backend mode where the...
CVE-2026-26150CRITICAL10Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net...
CVE-2026-24303CRITICAL9.6Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
CVE-2026-6942HIGH8.8radare2-mcp version 1.6.0 and earlier contains an os command injection vulnerability that allows remote attackers to exe...
CVE-2026-6941HIGH7.8radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to re...
CVE-2026-6940HIGH7.1radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recurs...
CVE-2026-6376HIGH8.7A weakness in SpiceJet’s public booking retrieval page permits full passenger booking details to be accessed using only ...
CVE-2026-6375HIGH8.7A vulnerability in SpiceJet’s booking API allows unauthenticated users to query passenger name records (PNRs) without an...
CVE-2026-28525HIGH8.2SWUpdate contains an integer underflow vulnerability in the multipart upload parser in mongoose_multipart.c that allows ...
CVE-2026-41279HIGH7.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-spe...
CVE-2026-41278HIGH7.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1...
CVE-2026-41277HIGH8.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignme...
CVE-2026-41276CRITICAL9.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerabil...
CVE-2026-41275HIGH7.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password re...
CVE-2026-41273HIGH8.2Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contain...
CVE-2026-41272HIGH7.1Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core securi...
CVE-2026-41271HIGH8.3Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side R...
CVE-2026-41270HIGH8.3Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side R...
CVE-2026-41269HIGH8.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow co...
CVE-2026-41268CRITICAL9.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vuln...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now