2026 CVE Vulnerabilities

48,557 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-46622HIGH8.1SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API...
CVE-2026-46489HIGH8.1SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any ...
CVE-2026-45175HIGH7.8Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent vali...
CVE-2026-52860HIGH7.8Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes recons...
CVE-2026-52859HIGH8.2Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/termin...
CVE-2026-52858HIGH7.8Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3...
CVE-2026-48547HIGH8.5KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrar...
CVE-2026-47189HIGH8.3Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.5, the A...
CVE-2026-47181HIGH8.7PenguinMod-BackendApi is the backend api for penguinmod. Prior to version 1.0.0, a NoSQL injection vulnerability in the ...
CVE-2026-47171HIGH8.8Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a nor...
CVE-2026-47170HIGH7.7Garlic-Hub manages digital signage network — devices, content, and playlists — from a single self-hosted interface. Prio...
CVE-2026-47169HIGH7.5Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a use...
CVE-2026-47163HIGH7.2Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.1, any g...
CVE-2026-47162HIGH8.8Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exi...
CVE-2026-46519HIGH8.8mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-...
CVE-2026-45178HIGH8.1Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endp...
CVE-2026-45176HIGH7.8Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged age...
CVE-2026-11774HIGH7.6An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(...
CVE-2026-48546HIGH8.5KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by expl...
CVE-2026-46697HIGH7.5Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unaut...
CVE-2026-3329HIGH7.5A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype N...
CVE-2026-49982HIGH8.2tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects ...
CVE-2026-44705HIGH8.2tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal...
CVE-2026-44496HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and befor...
CVE-2026-44495HIGH7.7Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contain...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now