2026 CVE Vulnerabilities

67,353 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93764MEDIUM6.5Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level enc...
CVE-2026-93763MEDIUM6.5A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that...
CVE-2026-93762CRITICAL9.8Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes...
CVE-2026-93761HIGH7.5An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library ma...
CVE-2026-93760HIGH8.2Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that...
CVE-2026-93759HIGH8.6Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the d...
CVE-2026-93753HIGH7.5deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properl...
CVE-2026-93752HIGH7.5CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to valida...
CVE-2026-93751MEDIUM6.5uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlon...
CVE-2026-93750MEDIUM5.9http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails t...
CVE-2026-93749HIGH7.5source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attacke...
CVE-2026-93748HIGH7.5http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-s...
CVE-2026-93432MEDIUM6.1A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails...
CVE-2026-92768MEDIUM5.5A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM...
CVE-2026-92747MEDIUM5A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running p...
CVE-2026-92745MEDIUM5A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process met...
CVE-2026-92702CRITICAL9.1Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions ...
CVE-2026-92701CRITICAL9.1Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions ...
CVE-2026-91127HIGH8.2File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applic...
CVE-2026-85058HIGH7.5Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last W...
CVE-2026-84992MEDIUM6.1md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt()...
CVE-2026-84975HIGH7.4PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuT...
CVE-2026-81182MEDIUM4.2SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a ...
CVE-2026-81181LOW3.7SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for pro...
CVE-2026-81180HIGH8.8SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Profess...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now