2026 CVE Vulnerabilities

48,366 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-55202HIGH8.8Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection,...
CVE-2026-55201HIGH7.4Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function ...
CVE-2026-55200HIGH8.3libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() t...
CVE-2026-55199HIGH7.5libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SS...
CVE-2026-50107HIGH8.6When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerabilit...
CVE-2026-32682HIGH7.1When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or...
CVE-2026-12529HIGH7.3A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1...
CVE-2026-11407HIGH8.6Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attacker...
CVE-2026-10696HIGH7.5Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier all...
CVE-2026-55198HIGH7.1Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows a...
CVE-2026-55197HIGH7.1Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows aut...
CVE-2026-53871HIGH8.6Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that ac...
CVE-2026-53869HIGH8.7Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to...
CVE-2026-48818HIGH7.5Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable t...
CVE-2026-9697HIGH7.4Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or s...
CVE-2026-6734HIGH8.8Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying t...
CVE-2026-47774HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7...
CVE-2026-30802HIGH8.2Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connex...
CVE-2026-30799HIGH8.1Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identit...
CVE-2026-2674HIGH8.1Out-of-bounds Write, Out-of-bounds Write, Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Servic...
CVE-2026-2467HIGH8.1Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags...
CVE-2026-9675HIGH7.5Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragme...
CVE-2026-53875HIGH7.1picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attackers to e...
CVE-2026-53872HIGH8.7picklescan before 0.0.35 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to r...
CVE-2026-35069HIGH8Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now