2026 CVE Vulnerabilities

48,557 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-49822HIGH7.7Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...
CVE-2026-49821HIGH7.7Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...
CVE-2026-46617HIGH8.7Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...
CVE-2026-46612HIGH8.8Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...
CVE-2026-45062HIGH8.1FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function...
CVE-2026-20252HIGH7.6In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.26...
CVE-2026-20251HIGH8.8In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.1...
CVE-2026-11417HIGH7.3OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) mi...
CVE-2026-53694HIGH7.3Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Arg...
CVE-2026-49759HIGH8.2Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to cra...
CVE-2026-46558HIGH8.3Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization ...
CVE-2026-45569HIGH8.1Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, om...
CVE-2026-45567HIGH8.3Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th...
CVE-2026-45565HIGH8.1Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, Es...
CVE-2026-25700HIGH7.2Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: thr...
CVE-2026-9045HIGH8.5During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manag...
CVE-2026-8637HIGH8.5A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could a...
CVE-2026-8335HIGH7.1A missing authentication check on the Aix‑DB "/llm/process_llm_out" endpoint allows unauthenticated clients to execute a...
CVE-2026-6090HIGH7.3A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticate...
CVE-2026-53689HIGH7.1libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection ...
CVE-2026-53475HIGH7.4A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connecti...
CVE-2026-53471HIGH7.7A flaw was found in migration-planner. The agent-API middleware processes JSON Web Tokens (JWTs) for authentication, but...
CVE-2026-53470HIGH8.1A flaw was found in migration-planner. An authenticated attacker could exploit an improper access control vulnerability ...
CVE-2026-53469HIGH8.1A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request ...
CVE-2026-45564HIGH8.8Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PO...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now