2026 CVE Vulnerabilities

69,888 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-29091HIGH8.1Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a ...
CVE-2026-29089HIGH8.8TimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgres extension. From ve...
CVE-2026-29087HIGH7.5@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server...
CVE-2026-28514CRITICAL9.8Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.8.6, 7.9.8, 7.10....
CVE-2026-29783HIGH7.8The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution thro...
CVE-2026-29082MEDIUM5.4Kestra is an event-driven orchestration platform. In versions from 1.1.10 and prior, Kestra’s execution-file preview ren...
CVE-2026-29075CRITICAL9.8Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behavi...
CVE-2026-29064HIGH8.2Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal...
CVE-2026-27777MEDIUM6.9Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-27764HIGH8.6The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ...
CVE-2026-27123——Rejected reason: Reason: This candidate was issued in error.
CVE-2026-27027MEDIUM6.9Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-26288CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat...
CVE-2026-26018HIGH7.5CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDN...
CVE-2026-26017MEDIUM6.3CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS acce...
CVE-2026-24696HIGH8.7The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc...
CVE-2026-20882HIGH8.7The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc...
CVE-2026-20748HIGH8.6The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ...
CVE-2026-2754HIGH7.5Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. ...
CVE-2026-2753HIGH7.5An Absolute Path Traversal vulnerability exists in Navtor NavBox. The application exposes an HTTP service that fails to ...
CVE-2026-2752MEDIUM5.3Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send ...
CVE-2026-26051CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat...
CVE-2026-1799——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate has been determined not to be a v...
CVE-2026-28106MEDIUM4.7URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Kings Plugins B2BKing Premium allows Phishing.This ...
CVE-2026-28080MEDIUM4.3Missing Authorization vulnerability in Rank Math Rank Math SEO PRO allows Exploiting Incorrectly Configured Access Contr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now