2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-77243HIGH8.8MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, EN...
CVE-2026-77242HIGH7.5MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, va...
CVE-2026-43643HIGH7.5Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing m...
CVE-2026-43642HIGH8.1Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing mo...
CVE-2026-18462HIGH7.3Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allow...
CVE-2026-18459HIGH8.7Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality. Th...
CVE-2026-18457HIGH8.3Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issu...
CVE-2026-94455HIGH7.1An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The a...
CVE-2026-87902HIGH8.1An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.ph...
CVE-2026-85740HIGH7.1LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parse...
CVE-2026-83803HIGH7.7Sentry is an error tracking and performance monitoring tool. From 23.11.0 until 26.7.0, Sentry instances with the reloca...
CVE-2026-83603HIGH8.4Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-sta...
CVE-2026-83599HIGH7.5Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates per...
CVE-2026-83598HIGH7.8Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powe...
CVE-2026-13087HIGH8.8A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/x...
CVE-2026-95806HIGH7.7MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point.  The phar...
CVE-2026-95655HIGH8.1Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated use...
CVE-2026-95654HIGH7.4Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization de...
CVE-2026-95653HIGH7.5Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead...
CVE-2026-94640HIGH7.5A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (...
CVE-2026-85055HIGH7.1Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.22.0, field-level read permission i...
CVE-2026-80150HIGH7.5Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, ...
CVE-2026-80149HIGH8.6Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, ...
CVE-2026-80148HIGH8.6Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, ...
CVE-2026-77633HIGH7.1Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now