2026 CVE Vulnerabilities

49,221 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-9516HIGH7.5Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter...
CVE-2026-9334HIGH7.3Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref i...
CVE-2026-10694HIGH7.3A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function i...
CVE-2026-44654HIGH8.1LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a sha...
CVE-2026-42504HIGH7.5Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
CVE-2026-40108HIGH7.1GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XS...
CVE-2026-31942HIGH7.1LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an In...
CVE-2026-25861HIGH8.2QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attack...
CVE-2026-8936HIGH8.2Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested dire...
CVE-2026-49443HIGH8.8authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the...
CVE-2026-49144HIGH7.1BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js ...
CVE-2026-49143HIGH8.8BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows u...
CVE-2026-47201HIGH8.5authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Sou...
CVE-2026-10620HIGH7.3A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index....
CVE-2026-10619HIGH7.3A vulnerability was detected in sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93a385485051800. This ...
CVE-2026-8036HIGH7.8Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially ...
CVE-2026-5385HIGH8.4An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item. Thi...
CVE-2026-5073HIGH7.5The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory...
CVE-2026-49120HIGH8.5Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authen...
CVE-2026-48594HIGH7.5Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of ...
CVE-2026-47265HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set wit...
CVE-2026-42342HIGH7.5React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 ...
CVE-2026-42211HIGH8.1React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps ...
CVE-2026-41577HIGH7.5authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response proces...
CVE-2026-34993HIGH7.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now