2026 CVE Vulnerabilities

50,196 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-70437LOW3.7Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison...
CVE-2026-70436MEDIUM4.3Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or p...
CVE-2026-70435MEDIUM4.2A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permissio...
CVE-2026-70434MEDIUM4.2A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to c...
CVE-2026-70433MEDIUM4.3Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission t...
CVE-2026-70432HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows atta...
CVE-2026-70431HIGH8.8Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Sc...
CVE-2026-70430LOW2.7Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as pa...
CVE-2026-70429HIGH8.1Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistent...
CVE-2026-70428MEDIUM4.3Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file pa...
CVE-2026-70427MEDIUM4.3Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names du...
CVE-2026-70426CRITICAL9In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2...
CVE-2026-44605MEDIUM5.5A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerabilit...
CVE-2026-17625HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1...
CVE-2026-10716HIGH7.5Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses Po...
CVE-2026-10128MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbit...
CVE-2026-9077HIGH8.5IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictio...
CVE-2026-8446HIGH7.5IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP)...
CVE-2026-7646MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other u...
CVE-2026-70607MEDIUM5.3Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,...
CVE-2026-20313HIGH7.7As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t...
CVE-2026-20312HIGH8.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t...
CVE-2026-20311MEDIUM6.3A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote atta...
CVE-2026-20310CRITICAL9.1As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t...
CVE-2026-20308MEDIUM4.3A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote atta...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now