2026 CVE Vulnerabilities

50,848 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-14587HIGH7.5Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask...
CVE-2026-9203HIGH8.5A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticate...
CVE-2026-9195CRITICAL9.3A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a...
CVE-2026-9193CRITICAL9.9An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and ...
CVE-2026-9192CRITICAL9.8An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allo...
CVE-2026-9190CRITICAL9.1An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 all...
CVE-2026-8709CRITICAL9.9An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server bef...
CVE-2026-8400CRITICAL9.8IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a f...
CVE-2026-7557CRITICAL9.1An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogi...
CVE-2026-7329CRITICAL9.9An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic...
CVE-2026-7327HIGH8.1An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server...
CVE-2026-7326HIGH7.5A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows ...
CVE-2026-70606MEDIUM5.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6...
CVE-2026-70605MEDIUM5.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,...
CVE-2026-70604HIGH7.4Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10...
CVE-2026-70603MEDIUM6Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6,...
CVE-2026-70602MEDIUM6.6Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,...
CVE-2026-70601HIGH7.5Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9,...
CVE-2026-70600LOW3.1Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,...
CVE-2026-70599MEDIUM5.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7,...
CVE-2026-70598LOW3.9Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10...
CVE-2026-70597MEDIUM6.3Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,...
CVE-2026-70596MEDIUM4.3Ghost is a Node.js content management system. From 4.9.0 until 6.54.1, an input validation issue allowed any staff user ...
CVE-2026-70595MEDIUM4Ghost is a Node.js content management system. From 6.26.0 until 6.54.1, a validation issue allowed some functionality, s...
CVE-2026-60053CRITICAL9.1Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Admin...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now