2026 CVE Vulnerabilities

67,251 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48521MEDIUM5.9Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-45381MEDIUM5.1Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint ins...
CVE-2026-94501HIGH8.8jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authent...
CVE-2026-94497HIGH8.3jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resour...
CVE-2026-94496HIGH8.3jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to mo...
CVE-2026-94495HIGH7.1jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authen...
CVE-2026-94494MEDIUM5jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenant...
CVE-2026-94414MEDIUM5.4jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authent...
CVE-2026-94413MEDIUM6.5jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve ...
CVE-2026-94412HIGH8.8jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authen...
CVE-2026-94411HIGH8.8jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authen...
CVE-2026-94403HIGH8.8A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library e...
CVE-2026-91167MEDIUM6Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.28.4, PUT /@warpgate/admin/api/users/...
CVE-2026-91166MEDIUM5.7Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path i...
CVE-2026-91165LOW2.4Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO...
CVE-2026-91164MEDIUM4.3Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authent...
CVE-2026-82165MEDIUM5.5Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vu...
CVE-2026-82163MEDIUM5.5Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. ...
CVE-2026-66280——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-63330HIGH7.7Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in war...
CVE-2026-63329MEDIUM4.9Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate...
CVE-2026-61749MEDIUM6.5InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or...
CVE-2026-61748MEDIUM4.3InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and Labe...
CVE-2026-61747MEDIUM4.3InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/importer/mappin...
CVE-2026-61746MEDIUM5.3InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and Pl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now