2026 CVE Vulnerabilities

47,106 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-11340HIGH8.3Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained b...
CVE-2026-14476HIGH8A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitiz...
CVE-2026-14474HIGH8.8A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD ...
CVE-2026-11610HIGH8.8A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SA...
CVE-2026-58384HIGH7.8A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation...
CVE-2026-8377HIGH8.2Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Colle...
CVE-2026-5799HIGH7.5Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime a...
CVE-2026-5730HIGH7.5Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime a...
CVE-2026-57871HIGH7.1Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overw...
CVE-2026-57869HIGH7.1Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstat...
CVE-2026-57868HIGH7.1MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects M...
CVE-2026-57867HIGH8.8MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit a...
CVE-2026-12277HIGH8.7The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input bef...
CVE-2026-34158HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-42200HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-42143HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34171HIGH8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34168HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34152HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34058HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34057HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34044HIGH7.7Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34035HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34034HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-53646HIGH7.7FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when a `Client...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now