2026 CVE Vulnerabilities

48,008 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-34594HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-57919HIGH7.8PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DA...
CVE-2026-56018HIGH7.5JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory ...
CVE-2026-56017HIGH7.5JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful t...
CVE-2026-53426HIGH8.2Allocation of Resources Without Limits or Throttling vulnerability in leandrocp MDEx allows Excessive Allocation. MDEx....
CVE-2026-43735HIGH8.1The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS ...
CVE-2026-43731HIGH8.8A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 ...
CVE-2026-43725HIGH7.1The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18....
CVE-2026-43724HIGH7.8The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26....
CVE-2026-43715HIGH8.8A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 a...
CVE-2026-43705HIGH8.8A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS ...
CVE-2026-43701HIGH7.1The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS ...
CVE-2026-58000HIGH8.8luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKe...
CVE-2026-57999HIGH8.8luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows...
CVE-2026-57960HIGH8.3Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated acc...
CVE-2026-57959HIGH8.2Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before as...
CVE-2026-57955HIGH8.5SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary C...
CVE-2026-57951HIGH7.1Mythic before 3.4.0.60 contains a broken hasura permission filter on the payload_build_step table with an always-satisfi...
CVE-2026-57950HIGH8.6ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderCon...
CVE-2026-57949HIGH7.1ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module...
CVE-2026-57948HIGH7.6Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the...
CVE-2026-57947HIGH8.5Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that al...
CVE-2026-56783HIGH7.1Parseable before 2.9.2 contains an information disclosure vulnerability in the notification-target API endpoints that re...
CVE-2026-56780HIGH7.7Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/passwor...
CVE-2026-56285HIGH8.6Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded defaul...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now