2026 CVE Vulnerabilities

66,372 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-35543MEDIUM5.3An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed...
CVE-2026-35542MEDIUM5.3An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. The remote image blocking feature can be bypassed...
CVE-2026-35541MEDIUM4.2An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Incorrect password comparison in the password plu...
CVE-2026-35540MEDIUM6.5An issue was discovered in Roundcube Webmail 1.6.0 before 1.6.14. Insufficient Cascading Style Sheets (CSS) sanitization...
CVE-2026-35539MEDIUM6.1An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. XSS exists because of insufficient HTML attachmen...
CVE-2026-35538LOW3.1An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsanitized IMAP SEARCH command arguments could l...
CVE-2026-5452LOW3.3A flaw has been found in UCC CampusConnect App up to 14.3.5 on Android. This vulnerability affects unknown code of the f...
CVE-2026-35537HIGH7.5An issue was discovered in Roundcube Webmail before 1.5.14 and 1.6.14. Unsafe deserialization in the redis/memcache sess...
CVE-2026-35536MEDIUM5.3In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .Req...
CVE-2026-35535HIGH7.8In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop befor...
CVE-2026-28815HIGH7.5A remote attacker can supply a short X-Wing HPKE encapsulated key and trigger an out-of-bounds read in the C decapsulati...
CVE-2026-35508MEDIUM6.1Shynet before 0.14.0 allows XSS in urldisplay and iconify template filters,
CVE-2026-35507MEDIUM6.5Shynet before 0.14.0 allows Host header injection in the password reset flow.
CVE-2026-33107CRITICAL9.8Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a netw...
CVE-2026-33105CRITICAL9.8Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over ...
CVE-2026-32213CRITICAL9.8Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-32211HIGH7.5Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information...
CVE-2026-32173HIGH7.5Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.
CVE-2026-26135HIGH8.8Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to ele...
CVE-2026-35467HIGH7.5The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other error...
CVE-2026-35466MEDIUM6.1XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from C...
CVE-2026-30252MEDIUM6.1Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l Zen...
CVE-2026-30251MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenSh...
CVE-2026-5420LOW2.5A security flaw has been discovered in Shinrays Games Goods Triple App up to 1.200. The affected element is an unknown f...
CVE-2026-35383MEDIUM6.9Bentley Systems iTwin Platform exposed a Cesium ion access token in the source of some web pages. An unauthenticated att...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now