2026 CVE Vulnerabilities

51,993 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-13723MEDIUM6.5A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrar...
CVE-2026-8339HIGH8.7A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclus...
CVE-2026-8338CRITICAL9.2A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026....
CVE-2026-67194HIGH7.1Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process...
CVE-2026-64560HIGH7.8In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader ...
CVE-2026-64559HIGH7.8In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl ...
CVE-2026-64558HIGH7.8In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in pkey_pckmo handler imple...
CVE-2026-54727HIGH8.2proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink ...
CVE-2026-54693HIGH8.2ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4...
CVE-2026-54680CRITICAL9.9Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd...
CVE-2026-54574HIGH8.2proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain ta...
CVE-2026-52791LOW2fuse-overlayfs is an implementation of overlayfs in FUSE for rootless containers. Prior to 1.17, the release-1.x C branc...
CVE-2026-51992Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse's PostgreSQL inte...
CVE-2026-20316MEDIUM5.3A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenti...
CVE-2026-18257MEDIUM5.6Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a cert...
CVE-2026-18255HIGH7.2A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repo...
CVE-2026-16729MEDIUM6.5undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before ...
CVE-2026-15144MEDIUM5.3@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Bec...
CVE-2026-13697CRITICAL9.1undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 an...
CVE-2026-67193MEDIUM6.9Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to...
CVE-2026-67192CRITICAL9.2Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthentic...
CVE-2026-67191CRITICAL9.8Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unaut...
CVE-2026-67188Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-66051Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-60113CRITICAL9.8AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnera...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now