2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-10591HIGH8.8Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remot...
CVE-2026-10047HIGH7.8The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler...
CVE-2026-10046HIGH7.8Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS INT 0x15 / E820 memor...
CVE-2026-9844HIGH8.8Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface mo...
CVE-2026-7312HIGH7.5CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152...
CVE-2026-7201HIGH8.8CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441...
CVE-2026-7195HIGH8.1CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152,...
CVE-2026-39555HIGH8.1Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askk...
CVE-2026-39553HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-39552HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-10622HIGH8.2Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged fun...
CVE-2026-10621HIGH7.5Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archi...
CVE-2026-42685HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Porta...
CVE-2026-42670HIGH7.5Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploitin...
CVE-2026-42669HIGH7.5Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Level...
CVE-2026-39551HIGH8.1Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbe...
CVE-2026-39550HIGH8.1Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects A...
CVE-2026-5422HIGH8.1A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check...
CVE-2026-3514HIGH7.5In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of UR...
CVE-2026-1784HIGH8.8The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found...
CVE-2026-8293HIGH7.5The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its ...
CVE-2026-25277HIGH8.8Memory corruption while using Strongbox due to buffer overflow.
CVE-2026-25276HIGH8.8Memory corruption while using Strongbox due to missing bounds check.
CVE-2026-25260HIGH7Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.
CVE-2026-25259HIGH7.8Memory corruption while processing multiple IOCTL command for escape operations.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now