2026 CVE Vulnerabilities

52,054 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-41135HIGH7.5free5GC UDR is the Policy Control Function (PCF) for free5GC, an an open-source project for 5th generation (5G) mobile c...
CVE-2026-41133HIGH8.8pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `r...
CVE-2026-41059HIGH8.2OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have ...
CVE-2026-5921HIGH8.9A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker t...
CVE-2026-4296HIGH8.8An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to byp...
CVE-2026-41058HIGH8.1WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `del...
CVE-2026-41057HIGH7.1WWBN AVideo is an open source video platform. In versions 29.0 and below, the CORS origin validation fix in commit `986e...
CVE-2026-41056HIGH8.1WWBN AVideo is an open source video platform. In versions 29.0 and below, the `allowOrigin($allowAll=true)` function in ...
CVE-2026-40926HIGH7.1WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endpoints — `objects/cat...
CVE-2026-6832HIGH8.1Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authentic...
CVE-2026-40945HIGH8.7Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, the full bearer token...
CVE-2026-40943HIGH8.7Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condition between session heartbeat processing...
CVE-2026-40931HIGH7.8Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 rel...
CVE-2026-40706HIGH8.4In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that al...
CVE-2026-6823HIGH8.3HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote cha...
CVE-2026-40938HIGH8.5Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and...
CVE-2026-40925HIGH8.3WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also r...
CVE-2026-40906HIGH8.8Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API...
CVE-2026-40905HIGH8.1LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, a password reset poisoning vulnerability was ...
CVE-2026-40895HIGH7.5follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows...
CVE-2026-35251HIGH7.5Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2026-35246HIGH7.5Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2026-35245HIGH7.5Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2026-35243HIGH7.8Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF ...
CVE-2026-35242HIGH7.5Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now