2026 CVE Vulnerabilities

67,265 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-75939HIGH7.4A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signature...
CVE-2026-75158MEDIUM4.3Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting ...
CVE-2026-71543HIGH7.5OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies...
CVE-2026-68919HIGH7GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious mater...
CVE-2026-61630MEDIUM4.2nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enable...
CVE-2026-61629HIGH7.5nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware ...
CVE-2026-61628HIGH8.1nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish...
CVE-2026-55870LOW2.3GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in...
CVE-2026-55625MEDIUM4.9GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/adm...
CVE-2026-55567HIGH7.8BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not ...
CVE-2026-55074HIGH8.2Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3....
CVE-2026-55071HIGH8.4MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0...
CVE-2026-55060LOW3.7GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforc...
CVE-2026-54584MEDIUM5.3mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including w...
CVE-2026-52743MEDIUM4.3GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a ...
CVE-2026-52742MEDIUM5.1GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical...
CVE-2026-52741HIGH7.5GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from comm...
CVE-2026-52740MEDIUM5.3GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names ca...
CVE-2026-94404HIGH7.1MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser ...
CVE-2026-94401HIGH8.3MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access i...
CVE-2026-94394MEDIUM6.3When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall ...
CVE-2026-94393MEDIUM6.4When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without prope...
CVE-2026-94387MEDIUM5.4Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_v...
CVE-2026-94382MEDIUM4.2Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-...
CVE-2026-93884——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now