2026 CVE Vulnerabilities

50,938 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-45728HIGH7.5Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path...
CVE-2026-44729HIGH8.7Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fil...
CVE-2026-44680HIGH7.6MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to @mikro-o...
CVE-2026-43982HIGH8.7Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go use...
CVE-2026-43981HIGH8.2Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protec...
CVE-2026-40384HIGH7.5An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerabili...
CVE-2026-24162HIGH7.8NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of unt...
CVE-2026-48692HIGH8.1FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The...
CVE-2026-48688HIGH7.5FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute...
CVE-2026-43935HIGH8.1e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset p...
CVE-2026-25112HIGH7.8A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.
CVE-2026-9552HIGH7.3A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown c...
CVE-2026-9551HIGH7.3A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of ...
CVE-2026-9550HIGH7.3A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0....
CVE-2026-46368HIGH8.8luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distribu...
CVE-2026-45082HIGH7.6Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability...
CVE-2026-42785HIGH8.6OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitra...
CVE-2026-42425HIGH8.6OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to exe...
CVE-2026-41401HIGH7.1libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly up...
CVE-2026-40034HIGH8.5gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmo...
CVE-2026-40033HIGH8.8FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers t...
CVE-2026-9544HIGH7.3A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by thi...
CVE-2026-48133HIGH7.5When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to r...
CVE-2026-48132HIGH8.1The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As...
CVE-2026-48131HIGH8.1The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage o...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now