2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-66750MEDIUM5.3Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to dow...
CVE-2026-66749HIGH7.1Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash th...
CVE-2026-66748HIGH8.8Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows user...
CVE-2026-66746MEDIUM5.4Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arb...
CVE-2026-62828MEDIUM5.4Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a netw...
CVE-2026-61609HIGH7.5Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limite...
CVE-2026-54593HIGH8.1Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2,...
CVE-2026-54545HIGH7.1wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 until 1.4.0, @wakaru/cli sanitizes bundle-controlle...
CVE-2026-51271Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51270Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51269Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51268Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51267Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51266Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51263Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-47483HIGH8.2NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could c...
CVE-2026-47427HIGH7.5GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server....
CVE-2026-45293HIGH8.6WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0....
CVE-2026-43910HIGH8.2Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. Fro...
CVE-2026-8164HIGH7.3Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desk...
CVE-2026-7521MEDIUM5.5Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deleti...
CVE-2026-6879LOW2`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index pred...
CVE-2026-67178HIGH7.8MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-t...
CVE-2026-67174CRITICAL9.2Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon-rendering...
CVE-2026-66713CRITICAL9.8Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Ap...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now