2026 CVE Vulnerabilities

47,538 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-72552HIGH7.5A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the ...
CVE-2026-72551HIGH8.8A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to execute...
CVE-2026-72550CRITICAL9.8An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to ex...
CVE-2026-72549MEDIUM5.3An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers ...
CVE-2026-72548HIGH7.5An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers ...
CVE-2026-72547HIGH7.1An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org...
CVE-2026-72546HIGH7.1An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org...
CVE-2026-72545HIGH7.5An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote ...
CVE-2026-72544HIGH7.5An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers ...
CVE-2026-72543HIGH7.5An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote ...
CVE-2026-72542MEDIUM5.4A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write ...
CVE-2026-72541MEDIUM6.5A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace membe...
CVE-2026-72540Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.
CVE-2026-72539MEDIUM6.5An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace mem...
CVE-2026-72538HIGH8.8An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code...
CVE-2026-72537HIGH8.8A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s...
CVE-2026-72536HIGH8.6A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mani...
CVE-2026-72535HIGH8.6A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint...
CVE-2026-72534HIGH8.8A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s...
CVE-2026-72533HIGH8.8An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypas...
CVE-2026-50237HIGH7.4A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace t...
CVE-2026-50236HIGH7.4An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are...
CVE-2026-13739HIGH8.8A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability relate...
CVE-2026-13738CRITICAL9.2CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Soft...
CVE-2026-13737CRITICAL9.2CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upg...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now