2026 CVE Vulnerabilities

49,873 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-44660HIGH7.5UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujso...
CVE-2026-8361HIGH7.5A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome
CVE-2026-8360HIGH7.5Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWe...
CVE-2026-8359HIGH7.5When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loaded to ...
CVE-2026-48064HIGH8.1pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, when a PAM service is...
CVE-2026-47272HIGH7.1pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, the pusb_pad_compare(...
CVE-2026-47161HIGH8.7RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configure...
CVE-2026-45134HIGH7.1LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and...
CVE-2026-45108HIGH8.4Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 2.0.0 to before 3.1.5 and 2.3.11, ...
CVE-2026-45104HIGH7.5MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always ...
CVE-2026-44886HIGH8.7Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web ap...
CVE-2026-44724HIGH7.8systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation...
CVE-2026-42197HIGH8.7RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a store...
CVE-2026-4868HIGH8.2GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 1...
CVE-2026-44635HIGH7.5Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does n...
CVE-2026-5509HIGH7.2An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an admin...
CVE-2026-48153HIGH8.5Budibase is an open-source low-code platform. Prior to 3.39.0, fetchToken in the OAuth2 SDK makes a POST to a builder-su...
CVE-2026-48152HIGH8.1Budibase is an open-source low-code platform. Prior to 3.39.0, the single-datasource GET and PUT routes are guarded by g...
CVE-2026-48151HIGH7.5Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schema-building endpoint is registered under ...
CVE-2026-48149HIGH8.1Budibase is an open-source low-code platform. Prior to 3.39.0, the Budibase Text component renders markdown by assigning...
CVE-2026-48146HIGH7.7Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token fetch function in packages/server/src/sd...
CVE-2026-46427HIGH7.7Budibase is an open-source low-code platform. Prior to 3.38.3, removeSecrets at packages/server/src/sdk/workspace/dataso...
CVE-2026-46426HIGH7.6Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload endpoint POST /api/attachments/process do...
CVE-2026-45717HIGH8.8Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. Th...
CVE-2026-45716HIGH8.8Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now