2026 CVE Vulnerabilities

68,105 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-10575HIGH8.8IBM MQ could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to a he...
CVE-2026-10030HIGH7.1IBM MQ Console allows authenticated non-administrative users to create and start queue managers due to improper authoriz...
CVE-2026-10027CRITICAL9.8IBM MQ could allow a remote attacker to cause a denial of service or execute arbitrary code due to a buffer overflow whe...
CVE-2026-93685MEDIUM5.4A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authenti...
CVE-2026-93676LOW3.2xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictio...
CVE-2026-93660MEDIUM6.5SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authe...
CVE-2026-93659HIGH8.1Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and a...
CVE-2026-93658HIGH7uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership ...
CVE-2026-93657HIGH7.5hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and R...
CVE-2026-93653MEDIUM5.5A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching t...
CVE-2026-93652HIGH7.5Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause Do...
CVE-2026-93576HIGH7.5A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed ...
CVE-2026-93573MEDIUM6.5A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` ...
CVE-2026-93569HIGH8.2A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 con...
CVE-2026-93568HIGH7.5A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTT...
CVE-2026-93567HIGH7.5A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly u...
CVE-2026-93566MEDIUM6.5A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that include...
CVE-2026-93565HIGH7.5A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes fr...
CVE-2026-93564HIGH7.5A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticat...
CVE-2026-93558HIGH7.5A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnera...
CVE-2026-93506MEDIUM6.3A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/...
CVE-2026-93505LOW3.5A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-...
CVE-2026-85511MEDIUM4.2A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oau...
CVE-2026-77929HIGH8.8ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote c...
CVE-2026-77928MEDIUM6.5ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now