2026 CVE Vulnerabilities

64,952 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41182MEDIUM5.3LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to version 0.5.19 of the JavaScri...
CVE-2026-41180HIGH7.5PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/...
CVE-2026-1923MEDIUM6.4The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’...
CVE-2026-6878MEDIUM5.6A vulnerability was identified in ByteDance verl up to 0.7.0. Affected is the function math_equal of the file prime_math...
CVE-2026-6874MEDIUM4.3A vulnerability was determined in ericc-ch copilot-api up to 0.7.0. This impacts an unknown function of the file /token ...
CVE-2026-5935CRITICAL9.8IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9.3, 9.4, 9.5, 9.6 TSSC/IMC could allow an unauthenticated us...
CVE-2026-5926MEDIUM6.5IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 ...
CVE-2026-4919MEDIUM4.8IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability allows an administrative use...
CVE-2026-4918MEDIUM4.8IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This vulnerability allows an administrat...
CVE-2026-4917MEDIUM4.9IBM Guardium Data Protection 12.1 could allow an administrative user to traverse directories on the system. An attacker ...
CVE-2026-41179CRITICAL9.8Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Starting i...
CVE-2026-41176CRITICAL9.8Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC end...
CVE-2026-40062HIGH8.7A path Traversal vulnerability exists in Ziostation2 v2.9.8.7 and earlier. A remote unauthenticated attacker may get sen...
CVE-2026-3621MEDIUM5.9IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.4 IBM WebSphere Application Server Liberty is vulnera...
CVE-2026-32679HIGH8.4The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the...
CVE-2026-29198CRITICAL9.8In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability c...
CVE-2026-1726MEDIUM4.8IBM Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2, 4.2.1, 5.0, and 5.1 enables privilege escalation, allowing unauthori...
CVE-2026-1352MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could...
CVE-2026-1274MEDIUM4.9IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a Bypass Business Logic vulnerability in the access m...
CVE-2026-1272MEDIUM4.3IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user a...
CVE-2026-4049——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-41455HIGH8.5WeKan before 8.35 contains a server-side request forgery vulnerability in webhook integration URL handling where the URL...
CVE-2026-41454HIGH8.7WeKan before 8.35 contains a missing authorization vulnerability in the Integration REST API endpoints that allows authe...
CVE-2026-41314MEDIUM6.5pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior ...
CVE-2026-41313MEDIUM6.5pypdf is a free and open-source pure-python PDF library. An attacker who uses a vulnerability present in versions prior ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now