2026 CVE Vulnerabilities

50,939 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-47682HIGH7.1CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0...
CVE-2026-18810HIGH7.3A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard...
CVE-2026-18657HIGH7.8An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated ac...
CVE-2026-18656HIGH7.8An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated a...
CVE-2026-16793HIGH8.8An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo ...
CVE-2026-16792MEDIUM6.1An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 micr...
CVE-2026-16791LOW3.9A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could ...
CVE-2026-70474HIGH7.6Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow...
CVE-2026-70473HIGH8.3Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow...
CVE-2026-70472HIGH7.1Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-...
CVE-2026-70471HIGH7.1Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow...
CVE-2026-69704HIGH7Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsan...
CVE-2026-69703CRITICAL9.8Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ th...
CVE-2026-69702HIGH7.1SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated a...
CVE-2026-68743HIGH7.1A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length...
CVE-2026-66300MEDIUM5SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. ...
CVE-2026-49435CRITICAL9.8Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote att...
CVE-2026-47781HIGH8.4PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-...
CVE-2026-47764HIGH8.4pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnera...
CVE-2026-13229HIGH7.1Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning end...
CVE-2026-0163CRITICAL9.8In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to rem...
CVE-2026-70470CRITICAL9.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validat...
CVE-2026-69264CRITICAL9.4Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Pyt...
CVE-2026-47763MEDIUM6.8pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm wri...
CVE-2026-47623HIGH8.2NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A succ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now