2026 CVE Vulnerabilities

51,076 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-62845MEDIUM4.7Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore driv...
CVE-2026-62246HIGH8.5Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane dat...
CVE-2026-5846HIGH7.6The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 cert...
CVE-2026-38709CRITICAL9.8TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2...
CVE-2026-18064HIGH8.2An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a s...
CVE-2026-12562HIGH8.8The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full...
CVE-2026-68503CRITICAL9.8LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships def...
CVE-2026-68502CRITICAL9.8LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2....
CVE-2026-68501MEDIUM6.5Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Syli...
CVE-2026-68500HIGH7.5Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Syli...
CVE-2026-68499MEDIUM6.2re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match ...
CVE-2026-66803CRITICAL10Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
CVE-2026-66418CRITICAL9.3OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attack...
CVE-2026-61526MEDIUM6.1AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through...
CVE-2026-55777MEDIUM5.3GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the b...
CVE-2026-55768HIGH8.7GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the b...
CVE-2026-54715HIGH7.1GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the b...
CVE-2026-52539CRITICAL9.1Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not se...
CVE-2026-35847CRITICAL9.8An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the Chec...
CVE-2026-67594CRITICAL9.8Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attac...
CVE-2026-67550MEDIUM5.7re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex again...
CVE-2026-67530MEDIUM6.4WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/...
CVE-2026-67529MEDIUM4.3OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /ap...
CVE-2026-67528MEDIUM4.3OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/custom_options/:id resol...
CVE-2026-67527HIGH7.6OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} acc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now