2026 CVE Vulnerabilities

64,997 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-22011HIGH7.6Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported version...
CVE-2026-22010HIGH7.5Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic...
CVE-2026-22009MEDIUM6.5Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2026-22008LOW3.7Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0...
CVE-2026-22007LOW2.9Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE...
CVE-2026-22006MEDIUM5.4Vulnerability in the PeopleSoft Enterprise HCM Human Resources product of Oracle PeopleSoft (component: Employee Snapsho...
CVE-2026-22005MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2026-22004MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are...
CVE-2026-22003MEDIUM6Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). ...
CVE-2026-22002MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2026-22001LOW2.7Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions t...
CVE-2026-21999MEDIUM5.3Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-...
CVE-2026-21998MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are a...
CVE-2026-21997HIGH8.5Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common...
CVE-2026-6819HIGH8.8HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enab...
CVE-2026-41320MEDIUM6.5Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.54.0 and 14.38.1, a special...
CVE-2026-40909MEDIUM6.5WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) c...
CVE-2026-40908MEDIUM5.3WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root execut...
CVE-2026-40907MEDIUM6.5WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/...
CVE-2026-40903CRITICAL9.1goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs has an ArtiPACKED vulnerability. ArtiPACKED can ...
CVE-2026-40890HIGH7.5The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing...
CVE-2026-40889MEDIUM6.5Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.2 and 16.4.2, authentica...
CVE-2026-40888MEDIUM6.5Frappe HR is an open-source human resources management solution (HRMS). Prior to versions 15.58.1 and 16.4.1, an authent...
CVE-2026-40887CRITICAL9.1Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and ...
CVE-2026-40885HIGH8.8goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials thr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now