2026 CVE Vulnerabilities

43,277 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-18556HIGH7.4Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass....
CVE-2026-55735HIGH7.5Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a vi...
CVE-2026-55734HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) a...
CVE-2026-55733HIGH7.5Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c...
CVE-2026-54894HIGH7.5Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom c...
CVE-2026-67355HIGH8.2guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain...
CVE-2026-67354HIGH8.2guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the...
CVE-2026-67352HIGH7.6luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows ...
CVE-2026-67344HIGH8.5ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYP...
CVE-2026-67343HIGH8.8ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing a...
CVE-2026-67337HIGH7.1better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is e...
CVE-2026-67333HIGH7.2better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redi...
CVE-2026-67331HIGH8.7better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator b...
CVE-2026-67329HIGH7.1@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization b...
CVE-2026-67328HIGH8.6@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling ...
CVE-2026-67327HIGH8.7better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable...
CVE-2026-67326HIGH7.3GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attac...
CVE-2026-67325HIGH8.8GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option p...
CVE-2026-67323HIGH8.6GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and g...
CVE-2026-67322HIGH8.7GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied rem...
CVE-2026-67320HIGH8.3axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hard...
CVE-2026-67311HIGH8.2Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fail...
CVE-2026-67309HIGH7.8Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider...
CVE-2026-67307HIGH7Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inven...
CVE-2026-67304HIGH8.7FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now