2026 CVE Vulnerabilities

68,738 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-21886HIGH8.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6....
CVE-2026-4318HIGH8.8A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. Affected is the function strcpy of the file /goform...
CVE-2026-3564CRITICAL9A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material ...
CVE-2026-4324MEDIUM5.4A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of use...
CVE-2026-3888HIGH7.8Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private ...
CVE-2026-4271HIGH7.5A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs...
CVE-2026-30911HIGH8.1Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop...
CVE-2026-28779HIGH7.5Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configu...
CVE-2026-28563MEDIUM4.3Apache Airflow versions 3.1.0 through 3.1.7 /ui/dependencies endpoint returns the full DAG dependency graph without filt...
CVE-2026-26929MEDIUM6.5Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersion listing API does not apply per-DAG authorization filterin...
CVE-2026-3634MEDIUM6.5A flaw was found in libsoup. An attacker controlling the value used to set the Content-Type header can inject a Carriage...
CVE-2026-3633MEDIUM6.5A flaw was found in libsoup. A remote attacker, by controlling the method parameter of the `soup_message_new()` function...
CVE-2026-3632MEDIUM5.5A flaw was found in libsoup, a library used by applications to send network requests. This vulnerability occurs because ...
CVE-2026-23241MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: audit: add missing syscalls to read class The "at"...
CVE-2026-4208HIGH8.8The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible M...
CVE-2026-4202MEDIUM4.3The extension fails to verify, if an authenticated user has permissions to access to redirects resulting in exposure of ...
CVE-2026-32586MEDIUM5.3Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectl...
CVE-2026-1323HIGH8.8The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker m...
CVE-2026-4312CRITICAL9.8GCB/FCB Audit Software developed by DrangSoft has a Missing Authentication vulnerability, allowing unauthenticated remot...
CVE-2026-3237MEDIUM4.3In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change ...
CVE-2026-4258HIGH7.7Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to miss...
CVE-2026-4308MEDIUM6.3A weakness has been identified in frdel/agent0ai agent-zero 0.9.7. This affects the function handle_pdf_document of the ...
CVE-2026-4307MEDIUM4.3A security flaw has been discovered in frdel/agent0ai agent-zero 0.9.7-10. The impacted element is the function get_abs_...
CVE-2026-2373MEDIUM5.3The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Informatio...
CVE-2026-0708MEDIUM6.5A flaw was found in libucl. A remote attacker could exploit this by providing a specially crafted Universal Configuratio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now