2026 CVE Vulnerabilities

43,284 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-65635HIGH8.3Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attack...
CVE-2026-41186HIGH7.5When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components ...
CVE-2026-16308HIGH7.5IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remo...
CVE-2026-14980HIGH8.8IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which c...
CVE-2026-14519HIGH7.5IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to r...
CVE-2026-12947HIGH7.5IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive infor...
CVE-2026-11980HIGH7.3IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.
CVE-2026-11897HIGH7.5IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sen...
CVE-2026-67351HIGH8.8Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and sessio...
CVE-2026-60075HIGH7.5Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substi...
CVE-2026-60074HIGH7.5Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric ran...
CVE-2026-5219HIGH8.3Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows C...
CVE-2026-57859HIGH7.7e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows a...
CVE-2026-56428HIGH8.1The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly...
CVE-2026-12722HIGH8.2Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel a...
CVE-2026-54368HIGH8.8CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows...
CVE-2026-54367HIGH8.8CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, w...
CVE-2026-54366HIGH8.7CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attack...
CVE-2026-54365HIGH8.7CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthe...
CVE-2026-41703HIGH7.6VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment pr...
CVE-2026-18381HIGH7.6A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom r...
CVE-2026-18378HIGH7.6A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able t...
CVE-2026-15397HIGH7.2The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and...
CVE-2026-22622HIGH8.8Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could al...
CVE-2026-22621HIGH8.3Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could al...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now