2026 CVE Vulnerabilities

43,284 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-27780CRITICAL9.8Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowin...
CVE-2026-26292CRITICAL9.8Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing ...
CVE-2026-26247CRITICAL9.1Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowi...
CVE-2026-26232CRITICAL9.1Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during...
CVE-2026-25718CRITICAL9.1Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processi...
CVE-2026-22874CRITICAL9.6Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
CVE-2026-22547CRITICAL9.1Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited templa...
CVE-2026-20896CRITICAL9.8Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any sour...
CVE-2026-20706CRITICAL9.1Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web arc...
CVE-2026-12481CRITICAL9.8A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deser...
CVE-2026-56015CRITICAL9.1Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length. add() passe...
CVE-2026-4321CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web...
CVE-2026-47898CRITICAL9.8Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common lib...
CVE-2026-14544CRITICAL9.8A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8...
CVE-2026-9079CRITICAL9.8libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the o...
CVE-2026-8927CRITICAL9.1When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails...
CVE-2026-8926CRITICAL9.1When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(withou...
CVE-2026-8925CRITICAL9.8The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing t...
CVE-2026-8924CRITICAL9.1A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffi...
CVE-2026-11856CRITICAL9.8Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then ...
CVE-2026-11564CRITICAL9.1libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches ...
CVE-2026-10536CRITICAL9.8A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CU...
CVE-2026-9725CRITICAL9.1The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletio...
CVE-2026-13768CRITICAL10Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub R...
CVE-2026-13368CRITICAL9.2WatchGuard Fireware OS contains a race condition leading to a use-after-free vulnerability in LDAP authentication for th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now