2026 CVE Vulnerabilities

48,334 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-48764HIGH8.2TypeBot is a chatbot builder tool. In versions prior to 3.17.2, SSRF validation is implemented by resolving a hostname o...
CVE-2026-53676HIGH8.6ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed c...
CVE-2026-48759HIGH7.1TypeBot is a chatbot builder tool. Versions 3.15.2 and below have an Insecure Direct Object Reference vulnerability thro...
CVE-2026-45617HIGH7.5LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,...
CVE-2026-45357HIGH7.5LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,...
CVE-2026-8050HIGH7.5In SignalRGB versions prior to 1.3.7.0, seven of the thirteen IOCTL handlers dereference the SystemBuffer pointer withou...
CVE-2026-50200HIGH7.5Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-50196HIGH7.5Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-50194HIGH8.2Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-48997HIGH7.1e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection vulnerability in the ...
CVE-2026-48989HIGH8.9Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP m...
CVE-2026-12530HIGH8.4Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK vers...
CVE-2026-49133HIGH7.1Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level pri...
CVE-2026-48979HIGH7.5PHP Standard Library (PSL) is set of APIs covering async, collections, networking, I/O, cryptography, terminal UI, etc. ...
CVE-2026-55202HIGH8.8Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection,...
CVE-2026-55201HIGH7.4Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function ...
CVE-2026-55200HIGH8.3libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() t...
CVE-2026-55199HIGH7.5libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SS...
CVE-2026-50107HIGH8.6When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerabilit...
CVE-2026-32682HIGH7.1When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or...
CVE-2026-12529HIGH7.3A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1...
CVE-2026-11407HIGH8.6Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attacker...
CVE-2026-10696HIGH7.5Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier all...
CVE-2026-55198HIGH7.1Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows a...
CVE-2026-55197HIGH7.1Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows aut...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now