2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-50125HIGH7.5MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpo...
CVE-2026-45726HIGH7.6Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a st...
CVE-2026-45720HIGH7Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML....
CVE-2026-92230HIGH7.5Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container thr...
CVE-2026-90997HIGH7.4A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics b...
CVE-2026-55062HIGH8.4uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget...
CVE-2026-54571HIGH8.7ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3...
CVE-2026-54524HIGH7.1Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the ...
CVE-2026-54504HIGH8.8MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13...
CVE-2026-54451HIGH8.2Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attack...
CVE-2026-54253HIGH8.2TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in pac...
CVE-2026-54239HIGH8.8Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertex...
CVE-2026-52851HIGH7.1Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an ob...
CVE-2026-52727HIGH7.2lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publica...
CVE-2026-19477HIGH7.8There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq).  This...
CVE-2026-92926HIGH7.3A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepar...
CVE-2026-54446HIGH8.1NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensi...
CVE-2026-52836HIGH8.7OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). Prior...
CVE-2026-44236HIGH7.1rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an unders...
CVE-2026-93296HIGH8.5MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event Gene...
CVE-2026-93295HIGH8.7MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user...
CVE-2026-93292HIGH8.5SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints tha...
CVE-2026-93203HIGH7.1In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: avoid CRC corruption due to parall...
CVE-2026-93201HIGH7.8In the Linux kernel, the following vulnerability has been resolved: dm-pcache: validate seg_id fields from persistent m...
CVE-2026-93196HIGH8.4In the Linux kernel, the following vulnerability has been resolved: nvdimm: virtio_pmem: refcount requests for token li...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now