2026 CVE Vulnerabilities

47,130 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-72544HIGH7.5An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers ...
CVE-2026-72543HIGH7.5An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote ...
CVE-2026-72542MEDIUM5.4A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write ...
CVE-2026-72541MEDIUM6.5A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace membe...
CVE-2026-72540Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.
CVE-2026-72539MEDIUM6.5An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace mem...
CVE-2026-72538HIGH8.8An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code...
CVE-2026-72537HIGH8.8A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s...
CVE-2026-72536HIGH8.6A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mani...
CVE-2026-72535HIGH8.6A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint...
CVE-2026-72534HIGH8.8A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s...
CVE-2026-72533HIGH8.8An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypas...
CVE-2026-50237HIGH7.4A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace t...
CVE-2026-50236HIGH7.4An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are...
CVE-2026-13739HIGH8.8A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability relate...
CVE-2026-13738CRITICAL9.2CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Soft...
CVE-2026-13737CRITICAL9.2CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upg...
CVE-2026-58231CRITICAL10SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially craf...
CVE-2026-73162MEDIUM5.3Affected versions of MISP cti-transmute expose several state-changing account operations as GET requests: * /acco...
CVE-2026-33922MEDIUM6.8A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to in...
CVE-2026-33921MEDIUM5.2The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver ...
CVE-2026-73161MEDIUM5.1Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feat...
CVE-2026-73160HIGH8.7Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoi...
CVE-2026-73159MEDIUM5.1Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's ...
CVE-2026-73158MEDIUM5.1Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can cont...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now