2026 CVE Vulnerabilities

51,085 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54722HIGH8.7DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_...
CVE-2026-54522MEDIUM5.4MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::B...
CVE-2026-51295Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51294Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51293Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51292Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51291Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51290Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-13379CRITICAL9.1The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS stat...
CVE-2026-13117HIGH8.1An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to tr...
CVE-2026-12996HIGH8.1A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to poten...
CVE-2026-12945HIGH7.1IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs throug...
CVE-2026-12940CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable ...
CVE-2026-12932HIGH8.1A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 all...
CVE-2026-11885HIGH8.4IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A careful...
CVE-2026-11771HIGH7.5OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the...
CVE-2026-67596MEDIUM6.9CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticate...
CVE-2026-58222HIGH8.8A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Do...
CVE-2026-58216MEDIUM5.3An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) servi...
CVE-2026-57862HIGH8.5Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass...
CVE-2026-52680CRITICAL9.8Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary...
CVE-2026-4978CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffi...
CVE-2026-48910MEDIUM6.5A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the mar...
CVE-2026-44617MEDIUM6.5LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constru...
CVE-2026-44616MEDIUM6.5LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escap...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now