2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-66299MEDIUM5.3Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache To...
CVE-2026-63727HIGH8.8Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in th...
CVE-2026-51261Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51260Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51259Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51254Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51252Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51251Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-67173MEDIUM5.1Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG i...
CVE-2026-66922MEDIUM5.1Pivotick used plain JavaScript objects as lookup tables indexed by caller-controlled graph node identifiers in its tree-...
CVE-2026-66921MEDIUM6.3Pivotick’s Markdown node-reference renderer failed to HTML-escape the attacker-controlled nodeName value before interpol...
CVE-2026-61487MEDIUM6.5Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated...
CVE-2026-59878HIGH7.5Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthe...
CVE-2026-7187HIGH8.8Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionalit...
CVE-2026-66920HIGH8.2Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data. The affec...
CVE-2026-66919MEDIUM6.9Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. Node labels and descriptions...
CVE-2026-66918HIGH8.2Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style.svgIcon property before in...
CVE-2026-66913MEDIUM6.9Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. An atta...
CVE-2026-65882MEDIUM6.1Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle w...
CVE-2026-65881HIGH7.5Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1...
CVE-2026-62436MEDIUM6.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-62435MEDIUM6.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-62434MEDIUM5.3A guest started with Populated on Demand enabled (PoD) can attempt to reclaim pages which aren't regular guest RAM. Thi...
CVE-2026-62433HIGH7.3Parts of the DM_OP handling code assumes the caller has provided the required number of buffers for the given operation ...
CVE-2026-62432HIGH7.3The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now