2026 CVE Vulnerabilities

67,723 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-70200CRITICAL9.8Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize...
CVE-2026-70009CRITICAL9.8Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attac...
CVE-2026-69865CRITICAL10Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elev...
CVE-2026-69399CRITICAL9.8Azure Arc Elevation of Privilege Vulnerability
CVE-2026-68791HIGH7.5Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network...
CVE-2026-65323——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-55946MEDIUM5.9Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut...
CVE-2026-93426HIGH8.5SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, ...
CVE-2026-93307MEDIUM4.3A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Coll...
CVE-2026-86688HIGH7.4Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier ...
CVE-2026-78668——Rejected reason: reserved but not needed
CVE-2026-76949CRITICAL9.1Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a re...
CVE-2026-73639CRITICAL9.1Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tR...
CVE-2026-73638MEDIUM6.2Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_...
CVE-2026-54767CRITICAL9.1WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php...
CVE-2026-54734CRITICAL10Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-suppl...
CVE-2026-54671HIGH8.8WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource arra...
CVE-2026-54670CRITICAL9.1WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/cont...
CVE-2026-54648MEDIUM6.5CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR tools in admin/sources/customers.gdpr.inc.php rely ...
CVE-2026-54647HIGH7.2CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates t...
CVE-2026-54646HIGH7.2CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator...
CVE-2026-54645MEDIUM4.8CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, ...
CVE-2026-54644MEDIUM6.1CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip...
CVE-2026-54643MEDIUM5.4CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.ph...
CVE-2026-54642MEDIUM5.3CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now