2026 CVE Vulnerabilities

52,006 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15228HIGH7.1Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a clust...
CVE-2026-66724MEDIUM5.3MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob u...
CVE-2026-66723HIGH7MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. ...
CVE-2026-65947HIGH7.3Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2
CVE-2026-65888CRITICAL9.8Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows acto...
CVE-2026-65887CRITICAL9.8Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method...
CVE-2026-65886HIGH7.5Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unaut...
CVE-2026-59247HIGH7.6Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute fo...
CVE-2026-54666HIGH8.3swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch...
CVE-2026-54664HIGH8.3swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch...
CVE-2026-54663MEDIUM6.1swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol...
CVE-2026-54662HIGH8.3swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-...
CVE-2026-54661HIGH8.3swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templat...
CVE-2026-54660HIGH7.4swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resol...
CVE-2026-12703HIGH8TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenti...
CVE-2026-9177CRITICAL9.4A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway Se...
CVE-2026-67217MEDIUM6.9cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a repl...
CVE-2026-67216HIGH7.5cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the...
CVE-2026-67215HIGH8.7cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON...
CVE-2026-67214HIGH7.5nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its no...
CVE-2026-67213HIGH7.5nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these fun...
CVE-2026-66490MEDIUM6.1Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2
CVE-2026-66489MEDIUM5.3Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2
CVE-2026-66488MEDIUM5.3Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2
CVE-2026-66400MEDIUM6.3Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php wh...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now