2026 CVE Vulnerabilities

51,104 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-11383MEDIUM5.4IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scri...
CVE-2026-67351HIGH8.8Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and sessio...
CVE-2026-60075HIGH7.5Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substi...
CVE-2026-60074HIGH7.5Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric ran...
CVE-2026-5219HIGH8.3Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows C...
CVE-2026-58218MEDIUM5.3A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY ...
CVE-2026-57859HIGH7.7e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows a...
CVE-2026-56428HIGH8.1The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly...
CVE-2026-41709LOW2.7VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform...
CVE-2026-12722HIGH8.2Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel a...
CVE-2026-59310CRITICAL9.8VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access ...
CVE-2026-59309CRITICAL9.8VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with n...
CVE-2026-54368HIGH8.8CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows...
CVE-2026-54367HIGH8.8CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, w...
CVE-2026-54366HIGH8.7CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attack...
CVE-2026-54365HIGH8.7CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthe...
CVE-2026-54364MEDIUM6.9CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inj...
CVE-2026-54363CRITICAL9.3CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to fo...
CVE-2026-47876CRITICAL9.3VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with ...
CVE-2026-41703HIGH7.6VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment pr...
CVE-2026-7260MEDIUM5.5Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP ...
CVE-2026-5582MEDIUM4.3The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24...
CVE-2026-18382MEDIUM6.8A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able...
CVE-2026-18381HIGH7.6A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom r...
CVE-2026-18378MEDIUM6.8A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now