2026 CVE Vulnerabilities

45,138 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-8085HIGH7.3A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) compo...
CVE-2026-53565HIGH8.5Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis ...
CVE-2026-15692HIGH8.8A weakness has been identified in Tenda BE12 Pro 16.03.66.23. This vulnerability affects the function fromSafeUrlFilter ...
CVE-2026-15691HIGH8.8A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. This affects the function fromSafeClientFilter of the...
CVE-2026-15389HIGH8.7A vulnerability relating to insufficient access control has been identified in the session management of the Sesame Time...
CVE-2026-54429HIGH7.4A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handl...
CVE-2026-9561HIGH8.8Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source o...
CVE-2026-58229HIGH8.2Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory o...
CVE-2026-15416HIGH8.9A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticate...
CVE-2026-15076HIGH7.5In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Ve...
CVE-2026-15075HIGH7.5In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx...
CVE-2026-10051HIGH7.5In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests...
CVE-2026-6851HIGH7An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in B...
CVE-2026-59674HIGH7.1A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user ...
CVE-2026-15677HIGH7.3A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /Job...
CVE-2026-15676HIGH7.3A security flaw has been discovered in code-projects Online Job Portal up to 1.0. The impacted element is an unknown fun...
CVE-2026-15675HIGH7.3A vulnerability was identified in code-projects Online Job Portal 1.0. The affected element is an unknown function of th...
CVE-2026-12583HIGH8.1The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through ...
CVE-2026-12511HIGH8.1The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downl...
CVE-2026-58233HIGH7.6SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted a...
CVE-2026-44752HIGH8.2SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted ...
CVE-2026-44745HIGH8.1SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurati...
CVE-2026-0487HIGH8.4SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location...
CVE-2026-58486HIGH8.3HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, HedgeDoc was ...
CVE-2026-58101HIGH7.5Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of service via NULL pointer dereference. X509V3_EXT_d2...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now