2026 CVE Vulnerabilities

53,500 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-63281MEDIUM4.8Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values coul...
CVE-2026-63280HIGH8.8Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manage...
CVE-2026-63265HIGH8Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension...
CVE-2026-13089HIGH7.5OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorith...
CVE-2026-9737HIGH7.1During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the m...
CVE-2026-64829CRITICAL9.1Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obta...
CVE-2026-14899HIGH7.5The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) ha...
CVE-2026-14881HIGH8.4When importing connections in Compass it is possible to override some connection options that are otherwise can't be cha...
CVE-2026-13078HIGH7.7A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered...
CVE-2026-13077HIGH7.1A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read...
CVE-2026-13076MEDIUM6.5An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by p...
CVE-2026-13075MEDIUM6.5An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via th...
CVE-2026-13074MEDIUM5.3An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combinati...
CVE-2026-13073MEDIUM4.3An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafte...
CVE-2026-13072HIGH8.1When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data du...
CVE-2026-13071MEDIUM6.5An authenticated user with read access can cause the mongod process to be terminated through certain aggregation express...
CVE-2026-13070MEDIUM6A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP respons...
CVE-2026-13069HIGH7.1An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a c...
CVE-2026-13068MEDIUM4.3An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate ac...
CVE-2026-13067HIGH7.2When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be v...
CVE-2026-13066HIGH7.1Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result i...
CVE-2026-13065HIGH7.1A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator...
CVE-2026-13064HIGH7.1Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in ...
CVE-2026-13063MEDIUM5.3An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-mem...
CVE-2026-13062HIGH7.1An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now