2026 CVE Vulnerabilities

47,534 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-14641HIGH7.3A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability i...
CVE-2026-14640HIGH7.3A vulnerability was found in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the f...
CVE-2026-14637HIGH8.2A security vulnerability has been detected in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 13fd582aaf49aeab7438acc0...
CVE-2026-12746HIGH8.1Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. The ...
CVE-2026-12740HIGH8.1Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 bu...
CVE-2026-14635HIGH7.3A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82...
CVE-2026-14534HIGH8.8Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubp...
CVE-2026-53362HIGH7.8In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation p...
CVE-2026-53361HIGH7.1In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). ...
CVE-2026-53360HIGH8.8In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ ...
CVE-2026-53359HIGH8.8In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to u...
CVE-2026-12196HIGH8.3HestiaCP panel cronjob feature is affected by a broken access control vulnerability. Low privilege users can modify the ...
CVE-2026-12195HIGH8.5myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary c...
CVE-2026-14622HIGH7.3A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. Th...
CVE-2026-12252HIGH7.8In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, Stanford...
CVE-2026-54424HIGH8.4An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Pri...
CVE-2026-58424HIGH8.9Permanent Fork PR Workflow Approval Gate Bypass
CVE-2026-58423HIGH7.7LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
CVE-2026-58421HIGH7.5Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
CVE-2026-58419HIGH7.5Notification API leaks private issue metadata after access revocation
CVE-2026-58299HIGH7.5Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execu...
CVE-2026-58297HIGH7.1Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized a...
CVE-2026-58296HIGH7.1Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized a...
CVE-2026-58295HIGH8.3Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-58294HIGH7.5Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now