2026 CVE Vulnerabilities

53,206 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-66390MEDIUM6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. Th...
CVE-2026-63077CRITICAL9.8In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin...
CVE-2026-24252HIGH7.8NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of...
CVE-2026-17531MEDIUM5A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality...
CVE-2026-17192HIGH8.5A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authentica...
CVE-2026-17191CRITICAL9.1An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this...
CVE-2026-66399HIGH8.5phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows admi...
CVE-2026-66398CRITICAL9.4phpMyFAQ before v4.1.6 contains a remote code execution vulnerability in the configuration API that allows authenticated...
CVE-2026-66397HIGH8.6phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, al...
CVE-2026-66396CRITICAL9.3SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cov...
CVE-2026-66395CRITICAL9.6SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler...
CVE-2026-66394CRITICAL9.3SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows ...
CVE-2026-59251HIGH7.5Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthentica...
CVE-2026-59250HIGH8.3Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corru...
CVE-2026-58227HIGH7.5The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a ...
CVE-2026-55953HIGH7.4The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in...
CVE-2026-55737HIGH7.5Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can ...
CVE-2026-54890HIGH7.5Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modu...
CVE-2026-51304Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51303Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51302Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51300Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51298Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51297Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-51296Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now