2026 CVE Vulnerabilities

50,983 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-44501HIGH7.1DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserialize...
CVE-2026-42595HIGH8.6Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/f...
CVE-2026-42594HIGH7.5Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine th...
CVE-2026-42591HIGH8.2Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/...
CVE-2026-42590HIGH8.2Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.30.0, The ExifTool metadata write blocklist in Got...
CVE-2026-42283HIGH7.8DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI se...
CVE-2026-42281HIGH8.6MagicMirror² is an open source modular smart mirror platform. Prior to 2.36.0, an unauthenticated Server-Side Request Fo...
CVE-2026-40893HIGH8.2Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly ...
CVE-2026-44375HIGH7.5Nerdbank.MessagePack is a NativeAOT-compatible MessagePack serialization library. Prior to 1.1.62, Nerdbank.MessagePack ...
CVE-2026-44216HIGH7.5Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and 44.0.1, Wasmtime's allocation logic for a WebA...
CVE-2026-42881HIGH8.4STIGQter is an open-source reimplementation of DISA's STIG Viewer. From 0.1.2 to before 1.2.7, an attacker can achieve l...
CVE-2026-42559HIGH8.8RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate's Streamable HTTP se...
CVE-2026-42186HIGH7.5OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace del...
CVE-2026-41937HIGH8.6Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_...
CVE-2026-41935HIGH7.1Vvveb before 1.0.8.3 contains an uncontrolled recursion vulnerability in the admin controller dispatch cycle where Base:...
CVE-2026-24712HIGH7.3Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.
CVE-2026-6638HIGH8.8SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table cre...
CVE-2026-6637HIGH8.8Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as th...
CVE-2026-6479HIGH7.5Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX ...
CVE-2026-6477HIGH8.8Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lsee...
CVE-2026-6476HIGH7.2SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitra...
CVE-2026-6475HIGH8.8Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite loca...
CVE-2026-6473HIGH8.8Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to un...
CVE-2026-5798HIGH7.1Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ en...
CVE-2026-4031HIGH7.5The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now