2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-67615HIGH8.8openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allows any authenticated ...
CVE-2026-94574HIGH7.8A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a har...
CVE-2026-89281HIGH8.4The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability...
CVE-2026-88419HIGH8.8An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=...
CVE-2026-88418HIGH8.8CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-c...
CVE-2026-88345HIGH7.5An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers sche...
CVE-2026-88344HIGH7.5An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers sche...
CVE-2026-88340HIGH7.6An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vu...
CVE-2026-77322HIGH7.5SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go...
CVE-2026-76715HIGH7.1A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-midd...
CVE-2026-76714HIGH7.2Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary co...
CVE-2026-76713HIGH7.2A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful explo...
CVE-2026-76712HIGH7.3A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information di...
CVE-2026-76711HIGH7.5A vulnerability exists in an Analytics and Location Engine (ALE) component where the impacted process improperly process...
CVE-2026-76710HIGH7.5A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure...
CVE-2026-63104HIGH8.1Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace me...
CVE-2026-62985HIGH7.5request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior ...
CVE-2026-61570HIGH7.5MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 5.5.5 ...
CVE-2026-59991HIGH7.5psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDI...
CVE-2026-58268HIGH7.5SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSingle in sip/parser_s...
CVE-2026-28325HIGH8.8SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability ...
CVE-2026-95862HIGH7.5A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi g...
CVE-2026-95861HIGH7.5A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniF...
CVE-2026-95831HIGH7.8Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfu...
CVE-2026-94462HIGH7.1Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/st...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now