2026 CVE Vulnerabilities

48,546 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-45012HIGH7.6ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authen...
CVE-2026-45011HIGH7.3ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site scripting vuln...
CVE-2026-44786HIGH7.5Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be...
CVE-2026-54361HIGH8.8MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegatio...
CVE-2026-54360HIGH8.4A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the...
CVE-2026-54359HIGH7.1MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. W...
CVE-2026-54358HIGH7.5An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accou...
CVE-2026-50287HIGH8.7AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a ...
CVE-2026-47260HIGH7.7Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via th...
CVE-2026-42851HIGH7.8Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty term...
CVE-2026-42850HIGH8.8Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the ...
CVE-2026-53408HIGH8.1Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7....
CVE-2026-50108HIGH8.7The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifyin...
CVE-2026-47138HIGH8.7Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-42947HIGH8.8A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently...
CVE-2026-42306HIGH7.2Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and ...
CVE-2026-12143HIGH7.5form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argumen...
CVE-2026-12043HIGH8.8Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote ...
CVE-2026-53406HIGH7.8Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0....
CVE-2026-48165HIGH7.2MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before ...
CVE-2026-48163HIGH7.2MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before ...
CVE-2026-47965HIGH7.8Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that...
CVE-2026-47216HIGH8.7Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is an unauthenticated denial-of...
CVE-2026-44171HIGH7.8MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before ...
CVE-2026-44168HIGH8MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now