2026 CVE Vulnerabilities

50,629 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-70599MEDIUM5.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7,...
CVE-2026-70598LOW3.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10...
CVE-2026-70597MEDIUM6.3Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,...
CVE-2026-70596MEDIUM4.3Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user ...
CVE-2026-70595MEDIUM4Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, s...
CVE-2026-60053CRITICAL9.1Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Admin...
CVE-2026-60023HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache An...
CVE-2026-53992MEDIUM6.1ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remot...
CVE-2026-50749MEDIUM6.5Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authentica...
CVE-2026-49331MEDIUM6.5A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy for...
CVE-2026-48912MEDIUM6.5Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ...
CVE-2026-48911HIGH7.5Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: throug...
CVE-2026-48834HIGH7.5Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: t...
CVE-2026-39924MEDIUM6.8Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid sess...
CVE-2026-39923CRITICAL9.2Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers t...
CVE-2026-32835Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-18531MEDIUM5.3IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use ...
CVE-2026-16442CRITICAL9.8A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authenti...
CVE-2026-15656MEDIUM4.3IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization tokens or session cook...
CVE-2026-15587CRITICAL9.4Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows...
CVE-2026-15572HIGH8.8A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mappe...
CVE-2026-13477HIGH8.8IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privilege...
CVE-2026-12762MEDIUM5.3IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensiti...
CVE-2026-12730LOW3.8IBM Business Automation Workflow containers and traditional 26.0.0, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 throug...
CVE-2026-10025CRITICAL9.8IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injec...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now