2026 CVE Vulnerabilities

47,535 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-27779HIGH7.5Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing sp...
CVE-2026-27775HIGH8.8Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allo...
CVE-2026-27771HIGH8.2Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which c...
CVE-2026-27660HIGH7.5Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permissio...
CVE-2026-27657HIGH7.5Gitea versions before 1.25.5 allow a user to change another user's primary email address.
CVE-2026-26307HIGH7.5Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume serve...
CVE-2026-26231HIGH8.5Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to...
CVE-2026-25712HIGH7.5Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and ...
CVE-2026-25038HIGH7.5Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
CVE-2026-24690HIGH7.5Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
CVE-2026-24451HIGH7.5Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing ...
CVE-2026-22555HIGH8.1Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCrea...
CVE-2026-20779HIGH7.1Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be ac...
CVE-2026-14606HIGH7.8A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function CAN_Receive in the ...
CVE-2026-14605HIGH7.8A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the l...
CVE-2026-58379HIGH7.3A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a rem...
CVE-2026-53478HIGH7.2Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-49815HIGH7.2Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-49814HIGH7.2Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-14460HIGH8.8Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Ar...
CVE-2026-14459HIGH8.8Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Softw...
CVE-2026-13341HIGH7.4A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow...
CVE-2026-10055HIGH8.5In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from...
CVE-2026-10054HIGH8.8In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSoc...
CVE-2026-47896HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucen...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now