2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-51274Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51273Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-18085MEDIUM6.9An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows A...
CVE-2026-18084MEDIUM6.1Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackB...
CVE-2026-16313HIGH7.6A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification ...
CVE-2026-8058MEDIUM4.5IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows a user to supply a password with a resou...
CVE-2026-7868MEDIUM6.5IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges an...
CVE-2026-7775MEDIUM4.8IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM St...
CVE-2026-67181MEDIUM5.4Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchroni...
CVE-2026-66754HIGH8.2Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that all...
CVE-2026-66753MEDIUM6.3tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return...
CVE-2026-66752MEDIUM6.3tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize ...
CVE-2026-66751MEDIUM5.4Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to ar...
CVE-2026-66750MEDIUM5.3Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to dow...
CVE-2026-66749HIGH7.1Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash th...
CVE-2026-66748HIGH8.8Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows user...
CVE-2026-66746MEDIUM5.4Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arb...
CVE-2026-62828MEDIUM5.4Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a netw...
CVE-2026-61609HIGH7.5Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limite...
CVE-2026-54593HIGH8.1Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2,...
CVE-2026-54545HIGH7.1wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 until 1.4.0, @wakaru/cli sanitizes bundle-controlle...
CVE-2026-51271Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51270Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51269Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51268Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now