2026 CVE Vulnerabilities

66,714 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-0522HIGH8.8A local file inclusion vulnerability in the upload/download flow of the VertiGIS FM application allows authenticated att...
CVE-2026-29014CRITICAL9.8MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote at...
CVE-2026-22768HIGH7.3Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low...
CVE-2026-22767HIGH7.3Dell AppSync, version(s) 4.6.0, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged att...
CVE-2026-25601MEDIUM6.7A vulnerability was identified in MEPIS RM, an industrial software product developed by Metronik. The application contai...
CVE-2026-24096HIGH8.8Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5...
CVE-2026-0932HIGH7.3Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in...
CVE-2026-23899HIGH8.8An improper access check allows unauthorized access to webservice endpoints.
CVE-2026-23898HIGH7.2Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
CVE-2026-21632MEDIUM5.4Lack of output escaping for article titles leads to XSS vectors in various locations.
CVE-2026-21631MEDIUM5.4Lack of output escaping leads to a XSS vector in the multilingual associations component.
CVE-2026-21630HIGH8.8Improperly built order clauses lead to a SQL injection vulnerability in the articles webservice endpoint.
CVE-2026-21629HIGH7.3The ajax component was excluded from the default logged-in-user check in the administrative area. This behavior was pote...
CVE-2026-1879MEDIUM6.3A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the fil...
CVE-2026-5261HIGH7.3A vulnerability was identified in Shandong Hoteam InforCenter PLM up to 8.3.8. The impacted element is the function uplo...
CVE-2026-4370CRITICAL10A vulnerability was identified in Juju from version 3.2.0 until 3.6.19 and from version 4.0 until 4.0.4, where the inter...
CVE-2026-34889MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force U...
CVE-2026-23411HIGH7.8In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race between freeing data and fs acce...
CVE-2026-23410HIGH7.8In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race on rawdata dereference There is...
CVE-2026-23409MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: apparmor: fix differential encoding verification D...
CVE-2026-23408HIGH7.8In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix double free of ns_name in aa_replace_...
CVE-2026-23407HIGH7.8In the Linux kernel, the following vulnerability has been resolved: apparmor: fix missing bounds check on DEFAULT table...
CVE-2026-23406HIGH7.8In the Linux kernel, the following vulnerability has been resolved: apparmor: fix side-effect bug in match_char() macro...
CVE-2026-23405MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: apparmor: fix: limit the number of levels of policy...
CVE-2026-23404MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: apparmor: replace recursive profile removal with it...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now