2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-94497HIGH8.3jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resour...
CVE-2026-94496HIGH8.3jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to mo...
CVE-2026-94495HIGH7.1jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authen...
CVE-2026-94412HIGH8.8jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authen...
CVE-2026-94411HIGH8.8jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authen...
CVE-2026-94403HIGH8.8A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library e...
CVE-2026-63330HIGH7.7Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in war...
CVE-2026-49810HIGH7.8Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log...
CVE-2026-17052HIGH7.8The Time-aware GPIO syscall verification handler z_vrfy_tgpio_pin_read_ts_ec() in drivers/timeaware_gpio/timeaware_gpio_...
CVE-2026-94488HIGH8.2Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in...
CVE-2026-62369HIGH8.1KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ...
CVE-2026-62182HIGH8.8KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ...
CVE-2026-48976HIGH8.1HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data...
CVE-2026-48975HIGH8.1HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceE...
CVE-2026-48826HIGH8.1HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1...
CVE-2026-94449HIGH7.5A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries an...
CVE-2026-84990HIGH8.8ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/config...
CVE-2026-83621HIGH8.1ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_bl...
CVE-2026-77560HIGH8.1Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensi...
CVE-2026-76898HIGH7.7draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.3.8, src/main/java/com/mxgraph/...
CVE-2026-63116HIGH8.8deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. From...
CVE-2026-62371HIGH8.8KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ...
CVE-2026-82412HIGH8.8ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scri...
CVE-2026-61687HIGH7.1Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, Va...
CVE-2026-55563HIGH8.9Feast is the open source feature store for AI and machine learning. Prior to 0.65.0, .github/workflows/pr_integration_te...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now