2026 CVE Vulnerabilities

51,238 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-35397HIGH8.8Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerabili...
CVE-2026-34596HIGH7Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of...
CVE-2026-34464HIGH8.8Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipe...
CVE-2026-34462HIGH7.8Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several P...
CVE-2026-34461HIGH7.8Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieI...
CVE-2026-34459HIGH8.8Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieS...
CVE-2026-34458HIGH8.8Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI in...
CVE-2026-33975HIGH8.3Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-...
CVE-2026-33489HIGH7.5CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL s...
CVE-2026-33324HIGH8.8SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the T...
CVE-2026-33190HIGH7.5CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-D...
CVE-2026-32936HIGH7.5CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts over...
CVE-2026-32934HIGH7.5CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven i...
CVE-2026-7855HIGH7.2A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /...
CVE-2026-42997HIGH7.7An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request aut...
CVE-2026-30923HIGH7.5ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsec...
CVE-2026-7851HIGH7.3A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The...
CVE-2026-25589HIGH8.8RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module ...
CVE-2026-25588HIGH8.8RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does no...
CVE-2026-25243HIGH8.8Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not proper...
CVE-2026-23631HIGH8.1Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacke...
CVE-2026-23479HIGH8.8Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not han...
CVE-2026-7865HIGH7.4A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argume...
CVE-2026-7412HIGH8.6In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validat...
CVE-2026-43070HIGH7.8In the Linux kernel, the following vulnerability has been resolved: bpf: Reset register ID for BPF_END value tracking ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now