2026 CVE Vulnerabilities

68,213 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-25937MEDIUM6.5GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, a malic...
CVE-2026-3856CRITICAL9.1IBM Db2 Recovery Expert for Linux, UNIX and Windows 5.5 IF 2 could allow an attacker to modify or corrupt data due to an...
CVE-2026-22727HIGH7.5Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on a...
CVE-2026-21994CRITICAL9.8Vulnerability in the Oracle Edge Cloud Infrastructure Designer and Visualisation Toolkit product of Oracle Open Source P...
CVE-2026-20643MEDIUM5.4A cross-origin issue in the Navigation API was addressed with improved input validation. This issue is fixed in Backgrou...
CVE-2026-1264MEDIUM6.5IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 ...
CVE-2026-4349MEDIUM6.3A vulnerability was determined in Duende IdentityServer4 up to 4.1.2. The affected element is an unknown function of the...
CVE-2026-32842HIGH7.1Edimax GS-5008PL firmware version 1.00.54 and prior contain an insecure credential storage vulnerability that allows att...
CVE-2026-32841CRITICAL9.2Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthen...
CVE-2026-32840MEDIUM5.4Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_na...
CVE-2026-32839MEDIUM6.5Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remot...
CVE-2026-32838MEDIUM5.9Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implemen...
CVE-2026-1376HIGH7.5IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to impr...
CVE-2026-1267MEDIUM6.5IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and a...
CVE-2026-2809MEDIUM6.7Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The succe...
CVE-2026-4359LOW3.7A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a cr...
CVE-2026-4358HIGH7.5A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-fre...
CVE-2026-4295HIGH8.5Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote una...
CVE-2026-4064HIGH8.3Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authen...
CVE-2026-3563MEDIUM5.5Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an auth...
CVE-2026-32981HIGH7.5A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due t...
CVE-2026-32837MEDIUM5.1miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vulnerabi...
CVE-2026-32836MEDIUM6.9dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled me...
CVE-2026-30707HIGH8.1An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control v...
CVE-2026-25936HIGH8.8GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an auth...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now