2026 CVE Vulnerabilities

47,998 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-13759HIGH8.8IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, Objec...
CVE-2026-12084HIGH7.5IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (CORS) which...
CVE-2026-11806HIGH7.5IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability...
CVE-2026-11595HIGH7.5IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the adm...
CVE-2026-10564HIGH8.2IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss...
CVE-2026-10129HIGH8.5IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in th...
CVE-2026-10513HIGH7.2The Webmention plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.8.0 v...
CVE-2026-9263HIGH8.1The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the l...
CVE-2026-8864HIGH7.3The HP Fan Control App might allow local escalation of privileges. An updated version of HP Fan Control App has been rel...
CVE-2026-58377HIGH8.6JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to ...
CVE-2026-58376HIGH7.6Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API u...
CVE-2026-58375HIGH8.7JimuReport through 2.5.0 exposes the POST /jmreport/auto/export endpoint without authentication: the handler is annotate...
CVE-2026-58372HIGH8.1SeaweedFS before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that allows...
CVE-2026-58176HIGH7.1RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (...
CVE-2026-58170HIGH8.3Vibe-Trading before 0.1.10 builds the proposal file path by joining a caller-supplied proposal identifier onto the broke...
CVE-2026-58169HIGH7.7Vibe-Trading before 0.1.10 contains a DNS rebinding authentication bypass vulnerability that allows remote attackers to ...
CVE-2026-58168HIGH8.8DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke...
CVE-2026-58167HIGH7.1Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HT...
CVE-2026-58165HIGH8.8OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated...
CVE-2026-49451HIGH7.5The OpenAPI.NET SDK contains a useful object model for OpenAPI documents in .NET along with common serializers to extrac...
CVE-2026-10653HIGH8.1The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf->ref and t...
CVE-2026-10652HIGH7.4Zephyr's DNS resolver (subsys/net/lib/dns) parses resource records from DNS responses in dns_unpack_answer(), which vali...
CVE-2026-48307HIGH8.8ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An...
CVE-2026-48285HIGH8.6ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that ...
CVE-2026-44949HIGH7A Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handler for versions 0.7.0...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now