2026 CVE Vulnerabilities

68,785 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54495MEDIUM4.3The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant wh...
CVE-2026-50285HIGH7.5Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs...
CVE-2026-50125HIGH7.5MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpo...
CVE-2026-45726HIGH7.6Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a st...
CVE-2026-45723LOW2.7Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.Creat...
CVE-2026-45720HIGH7Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML....
CVE-2026-92992MEDIUM6.3A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown functio...
CVE-2026-92230HIGH7.5Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container thr...
CVE-2026-90997HIGH7.4A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics b...
CVE-2026-55062HIGH8.4uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget...
CVE-2026-55061LOW1uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget...
CVE-2026-54649LOW2.1punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Pr...
CVE-2026-54617CRITICAL9.8GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote ...
CVE-2026-54571HIGH8.7ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3...
CVE-2026-54524HIGH7.1Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the ...
CVE-2026-54504HIGH8.8MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13...
CVE-2026-54451HIGH8.2Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attack...
CVE-2026-54253HIGH8.2TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in pac...
CVE-2026-54239HIGH8.8Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertex...
CVE-2026-52852MEDIUM6.5Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups a...
CVE-2026-52851HIGH7.1Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an ob...
CVE-2026-52727HIGH7.2lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publica...
CVE-2026-49292NONE0Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBV...
CVE-2026-47252CRITICAL9Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access...
CVE-2026-19477HIGH7.8There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq).  This...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now