2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-93435HIGH7.5redis-parser through 3.0.0 contains a denial of service vulnerability in the RESP protocol parser that allows malicious ...
CVE-2026-87886HIGH7.8Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin ...
CVE-2026-85917HIGH7.5Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a netw...
CVE-2026-85885HIGH8.8Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized...
CVE-2026-78501HIGH7.4Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business ...
CVE-2026-77903HIGH8.1Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a ne...
CVE-2026-68791HIGH7.5Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network...
CVE-2026-93426HIGH8.5SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, ...
CVE-2026-86688HIGH7.4Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier ...
CVE-2026-54671HIGH8.8WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource arra...
CVE-2026-54647HIGH7.2CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates t...
CVE-2026-54646HIGH7.2CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator...
CVE-2026-54634HIGH7.3Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld ...
CVE-2026-54612HIGH8.8Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until...
CVE-2026-54608HIGH7.1MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/Syste...
CVE-2026-54520HIGH8.1AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior ...
CVE-2026-54519HIGH8.8AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior ...
CVE-2026-54507HIGH8.4Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5...
CVE-2026-54506HIGH7.6Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5...
CVE-2026-54343HIGH8.7Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version ...
CVE-2026-53557HIGH7.7SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated use...
CVE-2026-53554HIGH7.3SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat...
CVE-2026-53534HIGH7.5JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef'...
CVE-2026-50158HIGH7.7yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool ...
CVE-2026-93393HIGH8.1A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platf...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now