2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-20271HIGH8.6As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t...
CVE-2026-20270HIGH8.6As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t...
CVE-2026-20269HIGH8.6As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t...
CVE-2026-20268HIGH8.6As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t...
CVE-2026-20263HIGH8.6A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauth...
CVE-2026-20200HIGH8.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with lo...
CVE-2026-20124HIGH7.7A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authe...
CVE-2026-17630HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation...
CVE-2026-17626HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitiv...
CVE-2026-17623HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to i...
CVE-2026-9203HIGH8.5A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticate...
CVE-2026-7327HIGH8.1An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server...
CVE-2026-7326HIGH7.5A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows ...
CVE-2026-70604HIGH7.4Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10...
CVE-2026-70601HIGH7.5Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9,...
CVE-2026-60023HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache An...
CVE-2026-48911HIGH7.5Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: throug...
CVE-2026-48834HIGH7.5Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: t...
CVE-2026-15572HIGH8.8A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mappe...
CVE-2026-13477HIGH8.8IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privilege...
CVE-2026-54876HIGH7.5Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by...
CVE-2026-17613HIGH7.5Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated ...
CVE-2026-16102HIGH8.1A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solut...
CVE-2026-15573HIGH8.1A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security ...
CVE-2026-12410HIGH7.8Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now