2026 CVE Vulnerabilities

65,269 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6370MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Mini Aj...
CVE-2026-30996HIGH7.5An issue in the file handling logic of the component download.php of SAC-NFe v2.0.02 allows attackers to execute a direc...
CVE-2026-30995HIGH8.6Slah CMS v1.5.0 and below was discovered to contain a SQL injection vulnerability via the id parameter in the vereador_v...
CVE-2026-30994HIGH7.5Incorrect access control in the config.php component of Slah v1.5.0 and below allows unauthenticated attackers to access...
CVE-2026-20186CRITICAL9.9A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitra...
CVE-2026-20184CRITICAL9.8A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed a...
CVE-2026-20180CRITICAL9.9A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitra...
CVE-2026-20170MEDIUM6.1A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, ...
CVE-2026-20161MEDIUM5.5A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low ...
CVE-2026-20152MEDIUM5.3A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could all...
CVE-2026-20148MEDIUM4.9A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal a...
CVE-2026-20147CRITICAL9.9A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary comman...
CVE-2026-20136MEDIUM6A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PI...
CVE-2026-20132MEDIUM4.8Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an au...
CVE-2026-20081MEDIUM6.5Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr...
CVE-2026-20078MEDIUM6.5Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr...
CVE-2026-20061MEDIUM6.5A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att...
CVE-2026-20060MEDIUM4.7A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a...
CVE-2026-20059MEDIUM6.1A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote a...
CVE-2026-5387CRITICAL9.3The vulnerability, if exploited, could allow an unauthenticated miscreant to perform operations intended only for Simula...
CVE-2026-30625CRITICAL9.8Upsonic 0.71.6 contains a remote code execution vulnerability in its MCP server/task creation functionality. The applica...
CVE-2026-30624HIGH8.6Agent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The a...
CVE-2026-30617HIGH8.6LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execut...
CVE-2026-30616HIGH7.3Jaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacke...
CVE-2026-30615HIGH8A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now