2026 CVE Vulnerabilities

51,445 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-6543HIGH8.8IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges o...
CVE-2026-6542HIGH8.1IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build ...
CVE-2026-6389HIGH7.8IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cl...
CVE-2026-40684HIGH7.5In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malfor...
CVE-2026-7435HIGH8.6SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed ...
CVE-2026-4503HIGH7.5IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow could allow an unauthenticated user to view other users' images due to...
CVE-2026-40912HIGH8.2Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high s...
CVE-2026-33451HIGH7.8CVE-2026-33451 is an arbitrary read/write vulnerability in the Secure Access Windows client prior to 14.50. Attackers w...
CVE-2026-33449HIGH7.5CVE-2026-33449 is a buffer overflow in a message handling function of the Secure Access client prior to 14.50. Attacker...
CVE-2026-7461HIGH7.5Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amaz...
CVE-2026-40904HIGH8.1Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-40601HIGH7.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-40600HIGH8.1Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-40595HIGH7.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-3833HIGH7.4A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstra...
CVE-2026-36765HIGH8.8An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticat...
CVE-2026-36762HIGH8.8An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers ...
CVE-2026-5174HIGH8.8Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation. This issue ...
CVE-2026-36960HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1....
CVE-2026-36340HIGH8.1An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose e...
CVE-2026-36959HIGH7.5U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. T...
CVE-2026-36958HIGH7.5A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concur...
CVE-2026-36957HIGH7.5Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI h...
CVE-2026-36956HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireles...
CVE-2026-7246HIGH7.2This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Clic...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now