2026 CVE Vulnerabilities

51,054 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-43983HIGH8.1Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, Th...
CVE-2026-43939HIGH7.3YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature acc...
CVE-2026-43938HIGH8.1YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNE...
CVE-2026-43937HIGH8.8YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects...
CVE-2026-42260HIGH8.2Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to ...
CVE-2026-32687HIGH7.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgr...
CVE-2026-8390HIGH7.3Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.
CVE-2026-8389HIGH8.8JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.
CVE-2026-6865HIGH7.1CWE-22: Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) vulnerability that could cause un...
CVE-2026-43916HIGH8.7pam_authnft is a PAM session module binding nftables firewall rules to authenticated sessions via cgroupv2 inodes. Prior...
CVE-2026-35071HIGH8.2Dell PowerScale InsightIQ, versions 6.0.0 through 6.2.0, contains an improper neutralization of special elements used in...
CVE-2026-4827HIGH8.7CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the networ...
CVE-2026-45218HIGH7.7Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Trave...
CVE-2026-45214HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elemento...
CVE-2026-45213HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 BEAR wo...
CVE-2026-45211HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExpe...
CVE-2026-42742HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPF...
CVE-2026-42741HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms V...
CVE-2026-41713HIGH8.2A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an uninte...
CVE-2026-41712HIGH7.5Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in ...
CVE-2026-2465HIGH8.8Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry an...
CVE-2026-8162HIGH7.5multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/f...
CVE-2026-8161HIGH7.5multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/f...
CVE-2026-8159HIGH7.5multiparty@4.2.3 and lower versions are vulnerable to denial of service via regular expression backtracking in the Conte...
CVE-2026-6001HIGH8.8Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now