2026 CVE Vulnerabilities

51,043 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-18394HIGH7.4Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to ob...
CVE-2026-57232LOW3.1Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7.0-RC1 through 5.7.8, the Feed Reader front-end mod...
CVE-2026-55824LOW2.6Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5.7.0-RC1 through 5.7.6, the crawler leaks auth cre...
CVE-2026-53505HIGH7.5Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion(<value>) fi...
CVE-2026-53504HIGH7.5Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expressio...
CVE-2026-53503HIGH7.5Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, ...
CVE-2026-53502HIGH8.7Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path...
CVE-2026-53501HIGH8.2Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypasse...
CVE-2026-53500HIGH8.2Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes...
CVE-2026-25552LOW3.7Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rat...
CVE-2026-18481HIGH7.3Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticate...
CVE-2026-18321MEDIUM4.7Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd
CVE-2026-55100HIGH8.7hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenat...
CVE-2026-54737HIGH7.3@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to ...
CVE-2026-54729HIGH8.7DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_...
CVE-2026-54725CRITICAL9.6vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1...
CVE-2026-34497MEDIUM5.4Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Syste...
CVE-2026-34495MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls F...
CVE-2026-34490MEDIUM5.5Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attac...
CVE-2026-21662CRITICAL9.8Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malic...
CVE-2026-67822CRITICAL9.8Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The fu...
CVE-2026-58048CRITICAL9.4Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.
CVE-2026-58047MEDIUM5.6HTTP Smuggling in cPanel allows potential leak of credentials.
CVE-2026-54707MEDIUM5.4OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien...
CVE-2026-54706MEDIUM4.8OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now