2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-46821HIGH7.7Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components)....
CVE-2026-46820HIGH8.5Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components)....
CVE-2026-46818HIGH7.4Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi...
CVE-2026-44657HIGH7.5Mantis Bug Tracker (MantisBT) is an open source issue tracker. Prior to 2.28.2, using show_inline=1 parameter and a vali...
CVE-2026-44655HIGH8.6Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 1.3.0 to 2.28.1, unescaped Project Name allows an at...
CVE-2026-42398HIGH7.7Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypas...
CVE-2026-42071HIGH7.2Mantis Bug Tracker (MantisBT) is an open source issue tracker. From 2.23.0 to 2.28.1, a missing authorization check in M...
CVE-2026-35277HIGH8.1Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. E...
CVE-2026-35266HIGH7.9Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. D...
CVE-2026-9039HIGH8.6A configuration weakness in the device’s remote management service allows an authenticated session to be established ove...
CVE-2026-9038HIGH8.6A stack-based buffer overflow vulnerability in the charging controller’s signal-processing logic allows an attacker with...
CVE-2026-49128HIGH8.7Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrThrow a...
CVE-2026-49127HIGH8.8Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be f...
CVE-2026-33590HIGH8.5Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access a...
CVE-2026-33462HIGH7.3A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with...
CVE-2026-32847HIGH8.7DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/mai...
CVE-2026-4944HIGH8.8vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in t...
CVE-2026-47333HIGH7.8Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an i...
CVE-2026-47331HIGH7.8Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivile...
CVE-2026-46509HIGH8.2deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, prototype pollution is possible when prope...
CVE-2026-45332HIGH7.5Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Acce...
CVE-2026-45044HIGH8.8RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelis...
CVE-2026-45042HIGH7.1RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper authorization in the Upload...
CVE-2026-45041HIGH8.7RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, crates/appauth/src/token.rs ships a ...
CVE-2026-44394HIGH8.1An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not p...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now