2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-70622HIGH7.1tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function t...
CVE-2026-10754HIGH8.6Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may ...
CVE-2026-72731HIGH7.1Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-l...
CVE-2026-72730HIGH8.7Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Edit...
CVE-2026-71576HIGH8.5A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming ...
CVE-2026-72718HIGH7goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system...
CVE-2026-66738HIGH8.8SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint ...
CVE-2026-48048HIGH7.5XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Sta...
CVE-2026-19433HIGH8.6Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before ...
CVE-2026-72692HIGH7.5A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote att...
CVE-2026-72691HIGH7.5An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote at...
CVE-2026-72690HIGH7.1An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to i...
CVE-2026-72689HIGH7.5A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticate...
CVE-2026-72688HIGH7.5A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote at...
CVE-2026-6374HIGH7.3Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executab...
CVE-2026-59233HIGH8.7Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authent...
CVE-2026-59090HIGH8.4A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` ...
CVE-2026-12984HIGH8.2Insufficiently Protected Credentials vulnerability in Zyxel Networks WAH7601 allows Retrieve Embedded Sensitive Data. T...
CVE-2026-72594HIGH7.6A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authentic...
CVE-2026-72591HIGH7.7A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make t...
CVE-2026-72586HIGH7.5A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to que...
CVE-2026-72584HIGH7.4A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attac...
CVE-2026-72582HIGH7.5A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to cras...
CVE-2026-72581HIGH8.6A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker...
CVE-2026-72579HIGH7.5An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now