2026 CVE Vulnerabilities

50,941 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-40172HIGH8.1authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PAT...
CVE-2026-40166HIGH7.1authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authent...
CVE-2026-39970HIGH8.5TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerability in the app.type...
CVE-2026-39968HIGH7.1TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via ...
CVE-2026-46727HIGH8.1An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getadd...
CVE-2026-39965HIGH7.7TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Reques...
CVE-2026-9255HIGH8.4Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to ex...
CVE-2026-37470HIGH7.3An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login p...
CVE-2026-36228HIGH7.3Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execu...
CVE-2026-34207HIGH7.6TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks valida...
CVE-2026-28445HIGH8.7Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders...
CVE-2026-9047HIGH7.6Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows...
CVE-2026-7325HIGH7.1Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authentica...
CVE-2026-9256HIGH8.1NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists w...
CVE-2026-8992HIGH8.8An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenti...
CVE-2026-9277HIGH8.1shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The ...
CVE-2026-8671HIGH7.5Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows R...
CVE-2026-44417HIGH7.5The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that anoth...
CVE-2026-5740HIGH7.5Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate ...
CVE-2026-5308HIGH7.5Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request bo...
CVE-2026-3473HIGH7.1Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file owne...
CVE-2026-25606HIGH8.7A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided by user into multip...
CVE-2026-9011HIGH7.5The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in al...
CVE-2026-8679HIGH7.5The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including...
CVE-2026-9018HIGH8.8The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now