2026 CVE Vulnerabilities

50,973 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-18733HIGH8.8A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors...
CVE-2026-18648MEDIUM5.3A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDat...
CVE-2026-18647HIGH7.3A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue ...
CVE-2026-18646MEDIUM5.5A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system...
CVE-2026-18645MEDIUM5.4A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /sys...
CVE-2026-69198MEDIUM6.9ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, ev...
CVE-2026-69192HIGH7.7ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 ac...
CVE-2026-69185HIGH7.5Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a sp...
CVE-2026-68981HIGH7.5Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding...
CVE-2026-68980CRITICAL9.1Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts throu...
CVE-2026-68979CRITICAL9.8Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization...
CVE-2026-67599HIGH8.6ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attacke...
CVE-2026-67598CRITICAL9.1Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that all...
CVE-2026-66296MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-sit...
CVE-2026-62354MEDIUM4.3Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients wit...
CVE-2026-58139MEDIUM6.5The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with S...
CVE-2026-48031CRITICAL9.1go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 202...
CVE-2026-47211HIGH8.4Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to ...
CVE-2026-18655HIGH7.1Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs....
CVE-2026-18654MEDIUM6.9Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v...
CVE-2026-18644MEDIUM5.4A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /...
CVE-2026-18641HIGH7.3A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by...
CVE-2026-18632MEDIUM6.3A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of ...
CVE-2026-18631MEDIUM6.3A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig ...
CVE-2026-59913HIGH7.8Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Criti...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now