2026 CVE Vulnerabilities

50,987 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-42463HIGH8.1SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cr...
CVE-2026-32993HIGH8.3Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated a...
CVE-2026-32992HIGH8.2SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the...
CVE-2026-29205HIGH8.6Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdav...
CVE-2026-45708HIGH7.2CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw <?php …...
CVE-2026-45229HIGH8.8Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated...
CVE-2026-45055HIGH8.1CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the...
CVE-2026-44418HIGH8.7EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in ...
CVE-2026-44380HIGH7.2MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerabili...
CVE-2026-42602HIGH8.1azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in...
CVE-2026-42561HIGH7.5Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service v...
CVE-2026-42304HIGH7.5Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.n...
CVE-2026-39358HIGH7.2CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities...
CVE-2026-21821HIGH8.3The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1...
CVE-2026-42552HIGH7.5Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the default error handler Engine::_error() writes the ...
CVE-2026-42551HIGH7.5Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Request::getMethod() unconditionally honors the X-HTTP...
CVE-2026-42550HIGH8.8Flight is an extensible micro-framework for PHP. Prior to 3.18.1, SimplePdo::insert(), SimplePdo::update(), and SimplePd...
CVE-2026-42548HIGH8.6Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Flight::jsonp() concatenates the ?jsonp= query paramet...
CVE-2026-33381HIGH8.1When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few ...
CVE-2026-33377HIGH7.1An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have wr...
CVE-2026-33376HIGH7.4When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask expl...
CVE-2026-8466HIGH8.2Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbo...
CVE-2026-44248HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT ...
CVE-2026-43970HIGH8.2Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticate...
CVE-2026-42587HIGH7.5Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpConte...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now