2026 CVE Vulnerabilities

49,883 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-46427HIGH7.7Budibase is an open-source low-code platform. Prior to 3.38.3, removeSecrets at packages/server/src/sdk/workspace/dataso...
CVE-2026-46426HIGH7.6Budibase is an open-source low-code platform. Prior to 3.38.2, the file upload endpoint POST /api/attachments/process do...
CVE-2026-45717HIGH8.8Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. Th...
CVE-2026-45716HIGH8.8Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected ...
CVE-2026-45715HIGH7.7Budibase is an open-source low-code platform. Prior to 3.38.1, the REST datasource integration (packages/server/src/inte...
CVE-2026-45548HIGH7.7Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automa...
CVE-2026-45090HIGH7.5Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, ParameterAnalysis in pk...
CVE-2026-45089HIGH8.2Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in R...
CVE-2026-45088HIGH7.5Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in R...
CVE-2026-45061HIGH7.7Budibase is an open-source low-code platform. Prior to 3.35.10, the Plugin URL upload endpoint (POST /api/plugin) valida...
CVE-2026-45047HIGH7.5bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes...
CVE-2026-44521HIGH8.8elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticate...
CVE-2026-44460HIGH7.4FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0,...
CVE-2026-44378HIGH7.5Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could ...
CVE-2026-44346HIGH8.8BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4....
CVE-2026-44345HIGH8.8BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4....
CVE-2026-42553HIGH7.1Cinny is a Matrix client. Prior to 4.10.3, A remote authenticated attacker who shares a room with a victim and has permi...
CVE-2026-38807HIGH8.8Insecure Permissions vulnerability in kvf-admin v1.0.0 allows a remote attacker to escalate privileges via the UserContr...
CVE-2026-44483HIGH8.2RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6...
CVE-2026-44473HIGH7.1Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged P...
CVE-2026-44328HIGH8.2free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management...
CVE-2026-44325HIGH7.5free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NRF root SBI endpoint POST /o...
CVE-2026-44322HIGH7.5free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF PATCH /3gpp-pfd-managemen...
CVE-2026-44321HIGH7.5free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management...
CVE-2026-44320HIGH7.3free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now