2026 CVE Vulnerabilities

66,632 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28805HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, mu...
CVE-2026-26928HIGH8.7SzafirHost downloads necessary files in the context of the initiating web page. When called, SzafirHost updates its dyna...
CVE-2026-26927MEDIUM5.1Szafir SDK Web is a browser plug-in that can run SzafirHost application which download the necessary files when launched...
CVE-2026-5331MEDIUM4.7A vulnerability was determined in OpenCart 4.1.0.3. This affects an unknown part of the file installer.php of the compon...
CVE-2026-5330MEDIUM6.5A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some ...
CVE-2026-5328MEDIUM6.3A weakness has been identified in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6. The impacted e...
CVE-2026-4636HIGH8.1A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) po...
CVE-2026-4634HIGH7.5A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted ...
CVE-2026-4325MEDIUM5.3A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace iso...
CVE-2026-4282HIGH7.4A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace iso...
CVE-2026-3872HIGH7.3A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass...
CVE-2026-34890MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mark O’Donnell MST...
CVE-2026-5327MEDIUM6.3A security flaw has been discovered in efforthye fast-filesystem-mcp up to 3.5.1. The affected element is the function h...
CVE-2026-23417MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bpf: Fix constant blinding for PROBE_MEM32 stores ...
CVE-2026-23416MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mm/mseal: update VMA end correctly on merge Previo...
CVE-2026-23415HIGH7.8In the Linux kernel, the following vulnerability has been resolved: futex: Fix UaF between futex_key_to_node_opt() and ...
CVE-2026-23414MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tls: Purge async_hold in tls_decrypt_async_wait() ...
CVE-2026-23413HIGH7.8In the Linux kernel, the following vulnerability has been resolved: clsact: Fix use-after-free in init/destroy rollback...
CVE-2026-23412HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: defer hook memory release until rcu...
CVE-2026-5326MEDIUM5.5A vulnerability was identified in SourceCodester Leave Application System 1.0. Impacted is an unknown function of the fi...
CVE-2026-32145HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in gleam-wisp wisp allows a denial of service via mul...
CVE-2026-5246HIGH8.1A vulnerability was determined in Cesanta Mongoose up to 7.20. Affected is the function mg_tls_verify_cert_signature of ...
CVE-2026-5245HIGH8.1A vulnerability was found in Cesanta Mongoose up to 7.20. This impacts the function handle_mdns_record of the file mongo...
CVE-2026-33617MEDIUM5.3An unauthenticated remote attacker can access a configuration file containing database credentials. This can result in a...
CVE-2026-33616HIGH7.5An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now