2026 CVE Vulnerabilities

48,297 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-9320HIGH7.5IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 a...
CVE-2026-9071HIGH7.5IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 a...
CVE-2026-8858HIGH8.8IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution an...
CVE-2026-8636HIGH7.5IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve use...
CVE-2026-56104HIGH8.8Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and i...
CVE-2026-54268HIGH7.5Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-50178HIGH8.8The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side...
CVE-2026-49241HIGH8.8The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4...
CVE-2026-41049HIGH7.1Incorrect caching of authentication between different users of the  qSnapper dbus service before version 1.3.3 allowed a...
CVE-2026-41048HIGH7.1Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local at...
CVE-2026-41046HIGH7.3A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to...
CVE-2026-41045HIGH7A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass...
CVE-2026-10845HIGH7.3IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorize...
CVE-2026-56448HIGH8.3A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e4...
CVE-2026-56447HIGH7.2MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path...
CVE-2026-56446HIGH7.2MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool...
CVE-2026-56425HIGH8.8The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorizat...
CVE-2026-56424HIGH8.8MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong ent...
CVE-2026-56423HIGH8.8MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The af...
CVE-2026-54100HIGH8.3A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishe...
CVE-2026-54099HIGH8.8A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR au...
CVE-2026-42129HIGH7.7A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endp...
CVE-2026-28381HIGH8.1The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the da...
CVE-2026-12602HIGH8.8Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assig...
CVE-2026-12581HIGH7.7EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a s...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now