2026 CVE Vulnerabilities

64,788 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-92729HIGH8.2SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the H...
CVE-2026-86043HIGH7.5Skipper is an HTTP router and reverse proxy for service composition. Prior to version 0.27.37, the opaAuthorizeRequestWi...
CVE-2026-86003HIGH7.5CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over...
CVE-2026-82399HIGH7.5CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over...
CVE-2026-81876HIGH7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio...
CVE-2026-81875HIGH7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio...
CVE-2026-79298HIGH8.4An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker...
CVE-2026-75516HIGH8.7The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. ...
CVE-2026-63325HIGH7.8Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/r...
CVE-2026-63126HIGH7.5Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.5 and 7.0.0-alpha04, Wire pro...
CVE-2026-46352HIGH7.5Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. St...
CVE-2026-38999HIGH7.5A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk_scheduler.c) of Monkey through commit 4fb0...
CVE-2026-92719HIGH7.5Quickwit through 0.9.0 fails to validate the host and scheme of the queue_url parameter in SQS file sources, allowing at...
CVE-2026-92718HIGH7.3Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content...
CVE-2026-92604HIGH8.1Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows d...
CVE-2026-92406HIGH7.3A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown f...
CVE-2026-85387HIGH7.1Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the sta...
CVE-2026-47094HIGH8.8SIMAC MyPHR 1.1 contains an insecure direct object reference (IDOR) vulnerability that allows authenticated attackers to...
CVE-2026-92602HIGH7.1TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigContro...
CVE-2026-92405HIGH7.3A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element i...
CVE-2026-92401HIGH7.3A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability aff...
CVE-2026-92399HIGH7.3A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/uti...
CVE-2026-86359HIGH8.5Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privile...
CVE-2026-86358HIGH8.8Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unau...
CVE-2026-85756HIGH7.5SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now