2026 CVE Vulnerabilities

66,618 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5332MEDIUM6.1A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of t...
CVE-2026-3692HIGH8.8In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may cr...
CVE-2026-35168HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, th...
CVE-2026-31933HIGH7.5Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause S...
CVE-2026-31932HIGH7.5Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can le...
CVE-2026-31931HIGH7.5Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the "tls.alpn" rule ke...
CVE-2026-30867MEDIUM6.5CocoaMQTT is a MQTT 5.0 client library for iOS and macOS written in Swift. Prior to version 2.2.2, a vulnerability exist...
CVE-2026-2737MEDIUM6.1A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a ma...
CVE-2026-2701HIGH8.8Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
CVE-2026-2699CRITICAL9.8Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted config...
CVE-2026-29782HIGH7.2OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, th...
CVE-2026-28805HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, mu...
CVE-2026-26928HIGH8.7SzafirHost downloads necessary files in the context of the initiating web page. When called, SzafirHost updates its dyna...
CVE-2026-26927MEDIUM5.1Szafir SDK Web is a browser plug-in that can run SzafirHost application which download the necessary files when launched...
CVE-2026-5331MEDIUM4.7A vulnerability was determined in OpenCart 4.1.0.3. This affects an unknown part of the file installer.php of the compon...
CVE-2026-5330MEDIUM6.5A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some ...
CVE-2026-5328MEDIUM6.3A weakness has been identified in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6. The impacted e...
CVE-2026-4636HIGH8.1A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) po...
CVE-2026-4634HIGH7.5A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted ...
CVE-2026-4325MEDIUM5.3A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace iso...
CVE-2026-4282HIGH7.4A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace iso...
CVE-2026-3872HIGH7.3A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass...
CVE-2026-34890MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O’Donnell MST...
CVE-2026-5327MEDIUM6.3A security flaw has been discovered in efforthye fast-filesystem-mcp up to 3.5.1. The affected element is the function h...
CVE-2026-23417MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Fix constant blinding for PROBE_MEM32 stores ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now