2026 CVE Vulnerabilities

67,251 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-61744MEDIUM6.5InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesi...
CVE-2026-58491CRITICAL9.3Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/provider...
CVE-2026-49810HIGH7.8Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log...
CVE-2026-17052HIGH7.8The Time-aware GPIO syscall verification handler z_vrfy_tgpio_pin_read_ts_ec() in drivers/timeaware_gpio/timeaware_gpio_...
CVE-2026-94488HIGH8.2Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in...
CVE-2026-93012CRITICAL9.8Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a...
CVE-2026-92382MEDIUM4.1An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves ...
CVE-2026-69190MEDIUM6.3Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for s...
CVE-2026-62369HIGH8.1KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ...
CVE-2026-62182HIGH8.8KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ...
CVE-2026-61745MEDIUM4.3InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the POST /api/machine/{pk}/restart/ endpoint in...
CVE-2026-61612MEDIUM5.7CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerU...
CVE-2026-55473MEDIUM6HomeBox is a home inventory and organization system. Prior to 0.26.0, the default-on BlockBogonNets and BlockCloudMetada...
CVE-2026-48976HIGH8.1HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data...
CVE-2026-48975HIGH8.1HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceE...
CVE-2026-48974MEDIUM5.4HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberA...
CVE-2026-48826HIGH8.1HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1...
CVE-2026-94449HIGH7.5A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries an...
CVE-2026-84990HIGH8.8ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/config...
CVE-2026-83621HIGH8.1ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_bl...
CVE-2026-79920CRITICAL9.9Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/t...
CVE-2026-77582MEDIUM6.9Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing di...
CVE-2026-77561MEDIUM5.3Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST...
CVE-2026-77560HIGH8.1Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensi...
CVE-2026-76898HIGH7.7draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.3.8, src/main/java/com/mxgraph/...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now