2026 CVE Vulnerabilities

64,772 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-53940HIGH8.8Conda is a system-level binary package and environment manager that runs on major operating systems and platforms. Prior...
CVE-2026-36467HIGH7.2Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticate...
CVE-2026-94184HIGH8.1A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail ...
CVE-2026-80110HIGH8.1A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcar...
CVE-2026-75939HIGH7.4A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signature...
CVE-2026-71543HIGH7.5OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies...
CVE-2026-68919HIGH7GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious mater...
CVE-2026-61629HIGH7.5nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware ...
CVE-2026-61628HIGH8.1nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish...
CVE-2026-55567HIGH7.8BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not ...
CVE-2026-55074HIGH8.2Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3....
CVE-2026-55071HIGH8.4MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0...
CVE-2026-52741HIGH7.5GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from comm...
CVE-2026-94404HIGH7.1MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser ...
CVE-2026-94401HIGH8.3MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access i...
CVE-2026-88807HIGH8.9A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject cod...
CVE-2026-88806HIGH7.5A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing th...
CVE-2026-94383HIGH8.6The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file ext...
CVE-2026-94381HIGH8.7MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read-only API...
CVE-2026-94374HIGH8.3MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event mode...
CVE-2026-84285HIGH8.8An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker...
CVE-2026-94368HIGH7.1A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object ...
CVE-2026-91866HIGH7.5A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work...
CVE-2026-91865HIGH7.5A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentia...
CVE-2026-91864HIGH7.5A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into me...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now