2026 CVE Vulnerabilities

65,279 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4523LOW3.7GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and ...
CVE-2026-19547HIGH7Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to t...
CVE-2026-15390CRITICAL9Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An...
CVE-2026-11796MEDIUM5.1Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet...
CVE-2026-10518MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 19.2.7, 19.3 before 19.3.3, and 19.4...
CVE-2026-102474MEDIUM4A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \u or \U escape, but the mu...
CVE-2026-102473MEDIUM5.5A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recur...
CVE-2026-96440HIGH7.1Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp AP...
CVE-2026-96431CRITICAL9.3Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agent...
CVE-2026-96430HIGH8.7Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2...
CVE-2026-96429CRITICAL9.3SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08...
CVE-2026-96428CRITICAL9.3SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 ...
CVE-2026-92142——Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC)...
CVE-2026-91085——Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command...
CVE-2026-91048——The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFact...
CVE-2026-91012——org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the c...
CVE-2026-84154CRITICAL9.9A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release...
CVE-2026-101169HIGH8.7In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set...
CVE-2026-86158HIGH7.7Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a ...
CVE-2026-86157MEDIUM5.6Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low...
CVE-2026-102293HIGH7.3A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the ...
CVE-2026-102292MEDIUM4.3A flaw has been found in coolbeans1212 MateisHomePage-Website up to ea2a4226deeca27ab1fb9df0552ec76444547811. Affected b...
CVE-2026-102290LOW3.5A vulnerability was determined in CodeCanyon Rocket LMS up to 2.2. This affects an unknown function of the component Stu...
CVE-2026-102264LOW3.5A vulnerability was found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The impacted element ...
CVE-2026-102263MEDIUM4.7A vulnerability has been found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The affected ele...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now