2026 CVE Vulnerabilities

50,911 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-44209HIGH7.5Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Env...
CVE-2026-9575HIGH7.3A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown...
CVE-2026-9574HIGH7.3A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code ...
CVE-2026-9573HIGH7.3A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of t...
CVE-2026-44833HIGH7.1Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows att...
CVE-2026-44832HIGH8.8Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permissio...
CVE-2026-8890HIGH8.8code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impe...
CVE-2026-4051HIGH7.2IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to e...
CVE-2026-3603HIGH7.1IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Int...
CVE-2026-9560HIGH7.8Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute ...
CVE-2026-8854HIGH7.5IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.
CVE-2026-8835HIGH7.3IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Admin...
CVE-2026-8834HIGH8IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administr...
CVE-2026-8620HIGH7.5IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server...
CVE-2026-7454HIGH7.8A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal...
CVE-2026-7452HIGH7.8A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal...
CVE-2026-7451HIGH7.8A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A ...
CVE-2026-48695HIGH8.1FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integra...
CVE-2026-48694HIGH8.1FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integr...
CVE-2026-44730HIGH7.2OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.7, an ...
CVE-2026-44728HIGH7.8Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel...
CVE-2026-44706HIGH8.5Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conver...
CVE-2026-44669HIGH8.7FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored c...
CVE-2026-44667HIGH8.7FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored c...
CVE-2026-24200HIGH7NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now