2026 CVE Vulnerabilities

43,347 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15562HIGH7.5A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and...
CVE-2026-15561HIGH7.5A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an at...
CVE-2026-15560HIGH8.1when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmars...
CVE-2026-15556HIGH8.1A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching th...
CVE-2026-15555HIGH8.8A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via ...
CVE-2026-15554HIGH7.4the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authenti...
CVE-2026-10579CRITICAL9.8A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no v...
CVE-2026-73156MEDIUM5.3Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap t...
CVE-2026-73155MEDIUM5.3Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first ...
CVE-2026-73140MEDIUM5.3Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report ex...
CVE-2026-19519MEDIUM4.3A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked...
CVE-2026-19418HIGH7.3The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, wher...
CVE-2026-19518MEDIUM6.5Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipu...
CVE-2026-19517MEDIUM6.5Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerabilit...
CVE-2026-19391MEDIUM6.5A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the ...
CVE-2026-16053HIGH8.5Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Tr...
CVE-2026-8158MEDIUM5.3The Signed Video Framework contained a  buffer overflow issue which could lead the application using this framework to ...
CVE-2026-6505MEDIUM5.1The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to priv...
CVE-2026-6181MEDIUM5.9The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after...
CVE-2026-5304MEDIUM5.7An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerabil...
CVE-2026-5303MEDIUM5.7The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to priv...
CVE-2026-4757HIGH7.2A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege...
CVE-2026-19516CRITICAL9.1A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the graf...
CVE-2026-18348MEDIUM4.1Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst...
CVE-2026-14549MEDIUM4.3The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now