2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-51267Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51266Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51263Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-47483HIGH8.2NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could c...
CVE-2026-47427HIGH7.5GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server....
CVE-2026-45293HIGH8.6WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0....
CVE-2026-43910HIGH8.2Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. Fro...
CVE-2026-8164HIGH7.3Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desk...
CVE-2026-7521MEDIUM5.5Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deleti...
CVE-2026-6879LOW2`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O(n^2)` time complexity when using XPath index pred...
CVE-2026-67178HIGH7.8MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-t...
CVE-2026-67174CRITICAL9.2Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon-rendering...
CVE-2026-66713CRITICAL9.8Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Ap...
CVE-2026-66299MEDIUM5.3Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache To...
CVE-2026-63727HIGH8.8Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in th...
CVE-2026-51261Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51260Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51259Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51254Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51252Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51251Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-67173MEDIUM5.1Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG i...
CVE-2026-66922MEDIUM5.1Pivotick used plain JavaScript objects as lookup tables indexed by caller-controlled graph node identifiers in its tree-...
CVE-2026-66921MEDIUM6.3Pivotick’s Markdown node-reference renderer failed to HTML-escape the attacker-controlled nodeName value before interpol...
CVE-2026-61487MEDIUM6.5Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now