2026 CVE Vulnerabilities

53,398 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15614HIGH7.5Logto silently fails to delete IdP-initiated SAML sessions, enabling session replay and reuse within the session’s valid...
CVE-2026-15612CRITICAL9.1Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication...
CVE-2026-15611CRITICAL9.1Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive Id...
CVE-2026-11804MEDIUM5.2Improper handling of insufficient permissions or privileges vulnerability in Tridium Niagara Framework on Windows, Linux...
CVE-2026-43823HIGH7.5When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the c...
CVE-2026-43820HIGH7.7NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to...
CVE-2026-8287MEDIUM4.3Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade ...
CVE-2026-65914MEDIUM6.1DOMPurify before 3.3.2 contains a mutation-XSS vulnerability when sanitized HTML is reinserted into special parsing cont...
CVE-2026-65913MEDIUM6.1DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass...
CVE-2026-65912MEDIUM6.1DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function ...
CVE-2026-65911MEDIUM6.1In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in int...
CVE-2026-65904MEDIUM4.7DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a diffe...
CVE-2026-65903MEDIUM6.1DOMPurify before 3.4.0 contains a logic error in the ADD_TAGS function where short-circuit evaluation allows forbidden t...
CVE-2026-65902MEDIUM6.1DOMPurify before 3.4.7 (affected versions <= 3.4.5) passes direct references to the module-level DEFAULT_ALLOWED_TAGS an...
CVE-2026-65901MEDIUM6.1DOMPurify through 3.4.6 contains a cross-site scripting vulnerability in IN_PLACE mode that trusts attacker-controlled n...
CVE-2026-65900MEDIUM6.1DOMPurify versions >=3.0.0 and before 3.4.8, when configured with SAFE_FOR_TEMPLATES together with a DOM output mode (RE...
CVE-2026-65899MEDIUM6.1DOMPurify 3.0.0 before 3.4.9 does not reset the retained Trusted Types policy when clearConfig() is called, so a DOMPuri...
CVE-2026-65898HIGH7.2DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute...
CVE-2026-65690HIGH8.8Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file ...
CVE-2026-65689CRITICAL9.8Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its datab...
CVE-2026-65688CRITICAL9.8Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font ...
CVE-2026-65687CRITICAL9.8Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG p...
CVE-2026-16735MEDIUM5.3A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function ...
CVE-2026-16733MEDIUM5.3A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell....
CVE-2026-14257HIGH7.5brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now