2026 CVE Vulnerabilities

43,284 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-63550HIGH7.1The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request mess...
CVE-2026-63362HIGH8.2An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cau...
CVE-2026-63035HIGH8.1A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attack...
CVE-2026-64816HIGH7.1RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_proce...
CVE-2026-63559HIGH8.7An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to r...
CVE-2026-62246HIGH8.5Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane dat...
CVE-2026-5846HIGH7.6The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 cert...
CVE-2026-18064HIGH8.2An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a s...
CVE-2026-12562HIGH8.8The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full...
CVE-2026-68500HIGH7.5Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Syli...
CVE-2026-55768HIGH8.7GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the b...
CVE-2026-54715HIGH7.1GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the b...
CVE-2026-67527HIGH7.6OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} acc...
CVE-2026-67207HIGH8.8Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authentic...
CVE-2026-67206HIGH8.8Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticat...
CVE-2026-66755HIGH7.5Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0....
CVE-2026-11536HIGH8.5IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX conne...
CVE-2026-66416HIGH8.8Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform stat...
CVE-2026-66415HIGH8.5Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated a...
CVE-2026-61536HIGH7.5Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool J...
CVE-2026-18245HIGH8.8Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authentic...
CVE-2026-18140HIGH8.7Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy...
CVE-2026-15978HIGH7.5SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two end...
CVE-2026-15977HIGH7.5SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyf...
CVE-2026-13444HIGH8.1IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creatin...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now