2026 CVE Vulnerabilities

48,546 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-47135HIGH8.7vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only inte...
CVE-2026-46340HIGH7.5Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport...
CVE-2026-45416HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-44894HIGH7.5Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the toke...
CVE-2026-44893HIGH7.5Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior t...
CVE-2026-28980HIGH8.7### Summary The `HTTPDecoder` in `NIOHTTP1` enforces no limit on the total size of an HTTP/1 message's header block or ...
CVE-2026-43671HIGH8.3### Summary A program using swift-nio is vulnerable to a potential out-of-bounds write when attacker-controlled index o...
CVE-2026-12066HIGH7.3A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the fi...
CVE-2026-11967HIGH8.5MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a ma...
CVE-2026-11879HIGH8.5MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading mali...
CVE-2026-47197HIGH7.2Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can...
CVE-2026-47196HIGH8.4Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the automod add command trims user input but does not re...
CVE-2026-47195HIGH7.1Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands check only guild-level p...
CVE-2026-9266HIGH7A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial...
CVE-2026-11848HIGH7.9The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing una...
CVE-2026-50645HIGH7.5There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache...
CVE-2026-50633HIGH8.1A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code exec...
CVE-2026-50632HIGH8.1A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache...
CVE-2026-50631HIGH7.4A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-u...
CVE-2026-11846HIGH8.1The  iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerabilit...
CVE-2026-11845HIGH8.6The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, al...
CVE-2026-12059HIGH8.8The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated ...
CVE-2026-45169HIGH8.6Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a v...
CVE-2026-44892HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final,...
CVE-2026-48612HIGH8Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow an...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now