2026 CVE Vulnerabilities

45,141 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-15685HIGH7.5Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote...
CVE-2026-15684HIGH7.3Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attac...
CVE-2026-15683HIGH7.5Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. This vulne...
CVE-2026-15680HIGH7.5Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability. This vulnerabil...
CVE-2026-15597HIGH7.3A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/2.php. This affects an unkno...
CVE-2026-58410HIGH7.1ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the fam...
CVE-2026-48364HIGH8.2ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that c...
CVE-2026-48363HIGH8.2ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that c...
CVE-2026-55773HIGH8.8CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisi...
CVE-2026-55771HIGH8.8CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisi...
CVE-2026-55772HIGH8.8CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisi...
CVE-2026-49972HIGH8.8Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve remo...
CVE-2026-49970HIGH8.8Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the File::sanitizePath() function that allows a...
CVE-2026-49969HIGH7.4Laravel-Mediable before 7.0.0 contains a server-side request forgery vulnerability that allows remote attackers to issue...
CVE-2026-26396HIGH7.5OpenBMB XAgent v1.0.0 and before is vulnerable to path traversal in the file() function in XAgent/XAgentServer/applicati...
CVE-2026-61463HIGH8.8Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to m...
CVE-2026-57432HIGH8.4Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack...
CVE-2026-59245HIGH8.1In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission reso...
CVE-2026-58065HIGH8.1The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling S...
CVE-2026-40553HIGH7.5Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue...
CVE-2026-40467HIGH7.5Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may ...
CVE-2026-15584HIGH7.5A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. The tool creates privileged d...
CVE-2026-61956HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام – همگام سازی ووکامرس و باسلام sync-basalam allo...
CVE-2026-61955HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم ...
CVE-2026-59521HIGH7.2Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Real Testimonials testimonial-free allows Object Inj...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now