2026 CVE Vulnerabilities

43,284 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-12942HIGH7.5IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker c...
CVE-2026-12733HIGH7.5IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.
CVE-2026-10545HIGH7.5IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect ...
CVE-2026-10535HIGH7.8IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
CVE-2026-9322HIGH7.5IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 a...
CVE-2026-62663HIGH7.5Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filt...
CVE-2026-54722HIGH8.7DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_...
CVE-2026-13117HIGH8.1An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to tr...
CVE-2026-12996HIGH8.1A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to poten...
CVE-2026-12945HIGH7.1IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs throug...
CVE-2026-12932HIGH8.1A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 all...
CVE-2026-11885HIGH8.4IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A careful...
CVE-2026-11771HIGH7.5OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the...
CVE-2026-58222HIGH8.8A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Do...
CVE-2026-57862HIGH8.5Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass...
CVE-2026-28814HIGH7.5Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain s...
CVE-2026-28813HIGH8.8Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommende...
CVE-2026-28811HIGH7.5Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to ver...
CVE-2026-15658HIGH8.1A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint t...
CVE-2026-10842HIGH7.5IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 T...
CVE-2026-6540HIGH7.5Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform UR...
CVE-2026-67349HIGH8.7OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environm...
CVE-2026-67348HIGH8.6Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authe...
CVE-2026-67346HIGH8.6Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url ...
CVE-2026-67345HIGH8.5MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in Defaul...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now