2026 CVE Vulnerabilities

46,876 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-35552HIGH8.1In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remot...
CVE-2026-10037HIGH8.8A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by th...
CVE-2026-60105HIGH8.6Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an...
CVE-2026-59818HIGH8.1etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is con...
CVE-2026-58525HIGH8.2Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature ...
CVE-2026-58208HIGH7.5NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2....
CVE-2026-58192HIGH8.6Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior...
CVE-2026-57480HIGH8.7Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a...
CVE-2026-56669HIGH7.5Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server commun...
CVE-2026-55596HIGH8.7Plate is a rich-text editor with AI and shadcn/ui. From 53.0.0 until 53.1.4, the media embed renderer trusts serialized ...
CVE-2026-55206HIGH8.7py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio...
CVE-2026-55195HIGH8.7py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio...
CVE-2026-54591HIGH8.1AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to...
CVE-2026-54528HIGH7.1JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandl...
CVE-2026-49866HIGH7.5libp2p is a JavaScript Implementation of libp2p networking stack. Prior to 16.0.0, @libp2p/gossipsub defaultDecodeRpcLim...
CVE-2026-35210HIGH7.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260326.0...
CVE-2026-15169HIGH7.5UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
CVE-2026-15163HIGH7.5Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of service
CVE-2026-0288HIGH7.5Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-...
CVE-2026-8800HIGH8.8Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transf...
CVE-2026-8651HIGH7.5Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects ...
CVE-2026-8650HIGH7.5Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Tr...
CVE-2026-60104HIGH8Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to t...
CVE-2026-59948HIGH7Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an...
CVE-2026-59939HIGH7.5httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression o...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now