2026 CVE Vulnerabilities

43,274 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-44182CRITICAL10Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kuber...
CVE-2026-44181CRITICAL10Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kuber...
CVE-2026-57075CRITICAL9.1YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64...
CVE-2026-53412CRITICAL9.8Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Wind...
CVE-2026-44180CRITICAL9.8Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kuber...
CVE-2026-38158CRITICAL9.8A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to acc...
CVE-2026-63089CRITICAL9.3WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation...
CVE-2026-15422CRITICAL9.1The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address ...
CVE-2026-54526CRITICAL9.9Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t...
CVE-2026-46515CRITICAL9.3Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call ...
CVE-2026-46512CRITICAL9.9Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template para...
CVE-2026-45336CRITICAL10HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring ...
CVE-2026-63087CRITICAL9.8Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a...
CVE-2026-57074CRITICAL9.1XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to ...
CVE-2026-57073CRITICAL9.1HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to...
CVE-2026-46621CRITICAL9.1Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamica...
CVE-2026-46562CRITICAL9.8Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScrip...
CVE-2026-45568CRITICAL9.1zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Fl...
CVE-2026-44632CRITICAL9.1Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs a...
CVE-2026-44596CRITICAL9.8Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handl...
CVE-2026-3031CRITICAL9.8Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg...
CVE-2026-59866CRITICAL9.3Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and...
CVE-2026-59865CRITICAL9.3Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInform...
CVE-2026-59864CRITICAL9.3Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (w...
CVE-2026-54733CRITICAL9.3The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration fo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now