2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-22734HIGH8.6Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UA...
CVE-2026-40318HIGH8.5SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttr...
CVE-2026-40259HIGH8.1SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and below, the /api/av/removeUnusedAttr...
CVE-2026-41113HIGH8.1sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remot...
CVE-2026-40308HIGH8.8My Calendar is a WordPress plugin for managing calendar events. In versions 3.7.6 and below, the mc_ajax_mcjs_action AJA...
CVE-2026-40248HIGH7.5free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the han...
CVE-2026-40247HIGH7.5free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the han...
CVE-2026-40246HIGH7.5free5GC is an open-source implementation of the 5G core network. In versions 1.4.2 and below of the UDR service, the han...
CVE-2026-40170HIGH7.5ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transpor...
CVE-2026-39313HIGH8.7mcp-framework is a framework for building Model Context Protocol (MCP) servers. In versions 0.2.21 and below, the readRe...
CVE-2026-40901HIGH8.8DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocit...
CVE-2026-40900HIGH8.8DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection...
CVE-2026-33207HIGH8.8DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection...
CVE-2026-6442HIGH8.3Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands t...
CVE-2026-33121HIGH8.8DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection...
CVE-2026-33084HIGH8.8DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection...
CVE-2026-41082HIGH7.8In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
CVE-2026-33083HIGH8.8DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection...
CVE-2026-2336HIGH8.8A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared ...
CVE-2026-6409HIGH7.1A Denial of Service (DoS) vulnerability exists in the Protobuf PHP library during the parsing of untrusted input. Malici...
CVE-2026-3324HIGH8.2Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due...
CVE-2026-37344HIGH7.2SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_lo...
CVE-2026-37343HIGH7.2SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_us...
CVE-2026-37342HIGH7.2SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_park...
CVE-2026-37341HIGH7.2SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_ca...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now