2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-11727HIGH8.1IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service...
CVE-2026-11726HIGH8.1IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or c...
CVE-2026-11725HIGH8.8IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to a...
CVE-2026-11716HIGH7.5IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or pote...
CVE-2026-93854HIGH7.2In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete...
CVE-2026-93852HIGH7.1In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project with...
CVE-2026-75894HIGH7.5In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrar...
CVE-2026-75893HIGH7.5In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg()  fun...
CVE-2026-93761HIGH7.5An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library ma...
CVE-2026-93760HIGH8.2Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that...
CVE-2026-93759HIGH8.6Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the d...
CVE-2026-93753HIGH7.5deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properl...
CVE-2026-93752HIGH7.5CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to valida...
CVE-2026-93749HIGH7.5source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attacke...
CVE-2026-93748HIGH7.5http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-s...
CVE-2026-91127HIGH8.2File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applic...
CVE-2026-85058HIGH7.5Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last W...
CVE-2026-84975HIGH7.4PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuT...
CVE-2026-81180HIGH8.8SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Profess...
CVE-2026-81179HIGH8.1SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset...
CVE-2026-69184HIGH7.5c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression poi...
CVE-2026-63458HIGH7.1Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenti...
CVE-2026-63445HIGH7.1Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoint...
CVE-2026-63199HIGH8.3Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the ...
CVE-2026-62279HIGH7.1LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an aut...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now