2026 CVE Vulnerabilities

64,788 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-85731HIGH8.8oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked w...
CVE-2026-71180HIGH7.8Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privi...
CVE-2026-71179HIGH7.8Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used ...
CVE-2026-68904HIGH7node-opcua is an OPC UA implementation for TypeScript and Node.js. From 2.0.0 until 2.170.0, node-opcua clients using th...
CVE-2026-59974HIGH7.8Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human language...
CVE-2026-42784HIGH7.4A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags su...
CVE-2026-92626HIGH7.5Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardint...
CVE-2026-92625HIGH7.5Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/r...
CVE-2026-61595HIGH7.7djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ...
CVE-2026-61593HIGH8.1djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ...
CVE-2026-17526HIGH7.2Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the...
CVE-2026-92566HIGH8.2DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that a...
CVE-2026-92380HIGH7.3A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file core...
CVE-2026-92366HIGH7.3A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search...
CVE-2026-92087HIGH8.1@fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route...
CVE-2026-88064HIGH8.8Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backst...
CVE-2026-84997HIGH7.5react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, Re...
CVE-2026-84860HIGH8.8ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints b...
CVE-2026-84858HIGH8.8ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Byp...
CVE-2026-82964HIGH8.8Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-...
CVE-2026-82410HIGH8.7Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middlew...
CVE-2026-80274HIGH7.5If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a val...
CVE-2026-79651HIGH7.5A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service respo...
CVE-2026-77412HIGH8.9RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP byte-ar...
CVE-2026-77410HIGH8.9RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the messa...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now