2026 CVE Vulnerabilities

52,080 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-35242HIGH7.5Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2026-35231HIGH7.5Vulnerability in the Oracle Financial Services Transaction Filtering product of Oracle Financial Services Applications (...
CVE-2026-35230HIGH7.5Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th...
CVE-2026-35229HIGH7.5Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.30 a...
CVE-2026-34320HIGH7.5Vulnerability in the Oracle Financial Services Customer Screening product of Oracle Financial Services Applications (com...
CVE-2026-34310HIGH7.5Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic...
CVE-2026-34309HIGH8.1Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported ve...
CVE-2026-34305HIGH7.5Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported ve...
CVE-2026-34297HIGH7.5Vulnerability in the Oracle HCM Common Architecture product of Oracle E-Business Suite (component: Knowledge Integration...
CVE-2026-34292HIGH7.2Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t...
CVE-2026-34291HIGH8.7Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core). Supported versions that ...
CVE-2026-34290HIGH7.5Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). The supp...
CVE-2026-34282HIGH7.5Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE...
CVE-2026-33518HIGH7.2An incorrect privilege assignment vulnerability exists in Esri Portal for ArcGIS 11.5 in Windows and Linux that allows h...
CVE-2026-22016HIGH7.5Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE...
CVE-2026-22011HIGH7.6Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: ADPatch). Supported version...
CVE-2026-22010HIGH7.5Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic...
CVE-2026-21997HIGH8.5Vulnerability in the Oracle Life Sciences Empirica Signal product of Oracle Life Science Applications (component: Common...
CVE-2026-6819HIGH8.8HKUDS OpenHarness prior to PR #156 remediation exposes plugin lifecycle commands including /plugin install, /plugin enab...
CVE-2026-40890HIGH7.5The package `github.com/gomarkdown/markdown` is a Go library for parsing Markdown text and rendering as HTML. Processing...
CVE-2026-40885HIGH8.8goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs leaks file-based ACL credentials thr...
CVE-2026-40883HIGH8.1goshs is a SimpleHTTPServer written in Go. From 2.0.0-beta.4 to 2.0.0-beta.5, goshs contains a cross-site request forger...
CVE-2026-40881HIGH7.5ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-network version 5.0.1, when dese...
CVE-2026-40880HIGH8.1ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and zebra-consensus version 5.0.2, a logic...
CVE-2026-40879HIGH7.5Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.19, when an attacker sends man...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now