2026 CVE Vulnerabilities

48,301 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-48895HIGH7.2URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some ...
CVE-2026-48141HIGH7.5There is a memory leak in NI grpc-device BeginSidebandStream that may result in denial of service due to memory exhausti...
CVE-2026-48140HIGH7.1There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigge...
CVE-2026-48139HIGH8.7There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attack...
CVE-2026-48138HIGH8.7There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check that may ...
CVE-2026-47339HIGH8.1Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under defaul...
CVE-2026-39998HIGH8.8Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in f...
CVE-2026-12104HIGH8.6OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25....
CVE-2026-56142HIGH8.8In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privileg...
CVE-2026-53915HIGH8.8In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration
CVE-2026-41156HIGH7.7Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reso...
CVE-2026-34192HIGH7.7Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an error path leading...
CVE-2026-11576HIGH7.5The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process t...
CVE-2026-46461HIGH7.8Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerability. A low privileg...
CVE-2026-8806HIGH8.7Expected Behavior Violation vulnerability in Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET...
CVE-2026-8805HIGH8.7Integer Overflow or Wraparound vulnerability in the EtherNet/IP function of Mitsubishi Electric MELSEC iQ-F Series FX5-E...
CVE-2026-52866HIGH7.1An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing l...
CVE-2026-50034HIGH7.1An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related...
CVE-2026-12050HIGH8.8SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-sup...
CVE-2026-12045HIGH8.8Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that th...
CVE-2026-12044HIGH8.8SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-su...
CVE-2026-56078HIGH8.8PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs w...
CVE-2026-56077HIGH7.1PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger component that allows ...
CVE-2026-56076HIGH8.6PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote a...
CVE-2026-56075HIGH8.8PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode appro...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now