2026 CVE Vulnerabilities

51,046 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-58047MEDIUM5.6HTTP Smuggling in cPanel allows potential leak of credentials.
CVE-2026-54707MEDIUM5.4OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien...
CVE-2026-54706MEDIUM4.8OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien...
CVE-2026-52856HIGH7.5Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a ...
CVE-2026-52855CRITICAL9.9Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{...
CVE-2026-67607HIGH8.2LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thr...
CVE-2026-59232MEDIUM5.3Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding ...
CVE-2026-59231MEDIUM5.3Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to...
CVE-2026-56571MEDIUM5.3HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions...
CVE-2026-56570MEDIUM5.3HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Va...
CVE-2026-56569LOW3.3HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal config...
CVE-2026-56568MEDIUM5.3HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It inv...
CVE-2026-56567LOW3.3HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of intern...
CVE-2026-52857MEDIUM5.5Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, un...
CVE-2026-18141HIGH8.2A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthentic...
CVE-2026-17566CRITICAL9.9pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query in...
CVE-2026-17351CRITICAL9The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_qu...
CVE-2026-17350MEDIUM5.4The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce...
CVE-2026-17349CRITICAL9.6/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of ...
CVE-2026-17348MEDIUM6.9In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's bef...
CVE-2026-17347HIGH8.8The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that ...
CVE-2026-17346HIGH8.8The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatin...
CVE-2026-16504CRITICAL9.8Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database passw...
CVE-2026-16503CRITICAL9.1Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces ...
CVE-2026-10686HIGH7.5Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now