2026 CVE Vulnerabilities

51,063 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15227MEDIUM5.3Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking t...
CVE-2026-46594MEDIUM5.1A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicio...
CVE-2026-46593HIGH8.6A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input...
CVE-2026-64607MEDIUM5.3HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection ma...
CVE-2026-62391HIGH8.1The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend...
CVE-2026-44615MEDIUM6.5Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker wi...
CVE-2026-17567MEDIUM5.3The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne...
CVE-2026-16843HIGH7.2Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validatio...
CVE-2026-18437MEDIUM5.3The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access ...
CVE-2026-18436MEDIUM5.3The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the ...
CVE-2026-15722HIGH7.5A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function ...
CVE-2026-11770HIGH7.5A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the Cle...
CVE-2026-10079HIGH8.5A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, AC...
CVE-2026-65313HIGH8.1A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-c...
CVE-2026-65311MEDIUM5.3The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoi...
CVE-2026-65310HIGH7.5ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configu...
CVE-2026-65309HIGH7.5ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible form...
CVE-2026-18218MEDIUM5.4A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attemp...
CVE-2026-18217MEDIUM4.7A flaw was found in the SAML protocol implementation of Keycloak, an open-source identity and access management solution...
CVE-2026-18215HIGH8.1Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization...
CVE-2026-18214HIGH8.1Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Wor...
CVE-2026-18211MEDIUM5.4A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is respo...
CVE-2026-18209MEDIUM4.7A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flow...
CVE-2026-18208MEDIUM6.5A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source...
CVE-2026-18206LOW3.7A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now