2026 CVE Vulnerabilities

64,788 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-92782HIGH8.1Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated a...
CVE-2026-92780HIGH8.8KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated...
CVE-2026-92779HIGH7.6Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set hel...
CVE-2026-92776HIGH8.1Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to a...
CVE-2026-92773HIGH7.1Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it...
CVE-2026-92772HIGH7.1Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks perm...
CVE-2026-92763HIGH8.1Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project arch...
CVE-2026-92762HIGH8.8Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather ...
CVE-2026-92761HIGH8.8WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform pri...
CVE-2026-92753HIGH7.1PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that ...
CVE-2026-92752HIGH8.3metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in ...
CVE-2026-92751HIGH8.1CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing ...
CVE-2026-92749HIGH8.1SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, all...
CVE-2026-92748HIGH8.8BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authent...
CVE-2026-76425HIGH7.6A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks ...
CVE-2026-76424HIGH7.2A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary f...
CVE-2026-76413HIGH8.2A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Softw...
CVE-2026-76412HIGH8.5A vulnerability in the remote diagnostics debugger of Cisco Secure FMC Software could allow an authenticated, remote att...
CVE-2026-76409HIGH8.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering t...
CVE-2026-63506HIGH8.8Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized a...
CVE-2026-62997HIGH7.7Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.P...
CVE-2026-20360HIGH8.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering t...
CVE-2026-20352HIGH8.6A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote att...
CVE-2026-20344HIGH8.8A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote ...
CVE-2026-20343HIGH7.5A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to downl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now