2026 CVE Vulnerabilities

48,546 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-7387HIGH8.8Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to req...
CVE-2026-6961HIGH7.6Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to san...
CVE-2026-6739HIGH7.2Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-...
CVE-2026-53982HIGH7.1Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker...
CVE-2026-53981HIGH7.6Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacke...
CVE-2026-3840HIGH7.1A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version strin...
CVE-2026-9638HIGH7.5Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built...
CVE-2026-8828HIGH8.8A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users...
CVE-2026-50091HIGH7.4Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses h...
CVE-2026-50011HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-50010HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-48748HIGH7.5Netty is a network application framework for development of protocol servers and clients. Starting in version 4.2.0.Fina...
CVE-2026-48059HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-48043HIGH7.5Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to ...
CVE-2026-48006HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-45833HIGH8.8A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacke...
CVE-2026-45832HIGH8.8All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorizatio...
CVE-2026-45831HIGH8.8The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project eva...
CVE-2026-45830HIGH8.8A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated us...
CVE-2026-40677HIGH7.7The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle atta...
CVE-2026-7368HIGH8.6The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether ...
CVE-2026-6211HIGH8.7Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Access...
CVE-2026-53721HIGH8.2Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4...
CVE-2026-47209HIGH8.6vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231)...
CVE-2026-47139HIGH8.6vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now