2026 CVE Vulnerabilities

65,632 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-93365MEDIUM6.5Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows authenticated users holding the Aut...
CVE-2026-93364MEDIUM4.3Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role ...
CVE-2026-93363MEDIUM4.3The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that a...
CVE-2026-91837HIGH7.8A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can explo...
CVE-2026-89032HIGH7.7BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that al...
CVE-2026-80432MEDIUM6Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows ...
CVE-2026-67421MEDIUM4.5RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ Man...
CVE-2026-67420LOW2.3RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ OAu...
CVE-2026-67419HIGH7.1RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a topic exch...
CVE-2026-67415MEDIUM5.9RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, the Shovel parameter parser converted at...
CVE-2026-67413MEDIUM6RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.23, 4.1.14, 4.2.9, and 4.3.3, the optional rabbitmq_j...
CVE-2026-67412MEDIUM6RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18, Federation u...
CVE-2026-67411MEDIUM6RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18, 4.0.23, 4.1.14, 4.2.9, and 4.3.3, native MQTT a...
CVE-2026-67410HIGH8.2RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.3.3 and 4.2.9, OAuth2 Client Secret Exposed via Unauthe...
CVE-2026-67409HIGH8.2RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9, 4.1.14, 4.0.23, and 3.13.18, JWKS Fetch Ig...
CVE-2026-67408HIGH7.1RabbitMQ is a messaging and streaming broker. From 4.1.0 until 4.3.3, 4.2.9, and 4.1.11, Stream Management Super-Stream ...
CVE-2026-67407MEDIUM5.1RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3 and 4.2.9 and 4.1.14 and 4.0.23, Incomplete fix for...
CVE-2026-67406MEDIUM4.6RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, 4.2.9, 4.1.14, and 4.0.23, Shovel does not format ...
CVE-2026-67242MEDIUM6.3RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, OAuth2 isinteger(Exp) guard skips token-...
CVE-2026-67241MEDIUM4.8RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, AMQP 1.0 management exchange.declare ski...
CVE-2026-67239HIGH7.6RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18 and 4.0.23 and 4.1.14 and 4.2.9 and 4.3.3, Store...
CVE-2026-67237HIGH7.5RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, set_token_auth/2 inserted a bearer token...
CVE-2026-67234LOW2.3RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, get_auth_mechanism/1 used term_to_binary...
CVE-2026-67230MEDIUM6.3RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the Web STOMP WebSoc...
CVE-2026-67227MEDIUM5.9RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7 and 4.3.1, Atom exhaustion: t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now