2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-39981HIGH8.8AGiXT is a dynamic AI Agent Automation Platform. Prior to 1.9.2, the safe_join() function in the essential_abilities ext...
CVE-2026-39980HIGH7.2OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the...
CVE-2026-39911HIGH8.8Hashgraph Guardian through version 3.5.1, fixed in commit 45fbe2f, contains an unsandboxed JavaScript execution vulnerab...
CVE-2026-30478HIGH8.8A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer for Windows version 5 allows attackers to escalat...
CVE-2026-1584HIGH7.5A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially cra...
CVE-2026-5961HIGH7.3A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This vulnerability affects u...
CVE-2026-40046HIGH7.5Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for...
CVE-2026-39976HIGH7.1Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Byp...
CVE-2026-39974HIGH8.5n8n-MCP is a Model Context Protocol (MCP) server that provides AI assistants with comprehensive access to n8n node docum...
CVE-2026-39972HIGH7.1Mercure is a protocol for pushing data updates to web browsers and other HTTP clients in a battery-efficient way. Prior ...
CVE-2026-39959HIGH7.1Tmds.DBus provides .NET libraries for working with D-Bus from .NET. Tmds.DBus and Tmds.DBus.Protocol are vulnerable to m...
CVE-2026-39942HIGH8.8Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id}...
CVE-2026-4878HIGH7A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition...
CVE-2026-39853HIGH7.8osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.12, A stack buffer overflow vul...
CVE-2026-39843HIGH7.7Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw ...
CVE-2026-35205HIGH7.8Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (...
CVE-2026-35204HIGH8.6Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installe...
CVE-2026-34020HIGH7.5Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint us...
CVE-2026-33266HIGH7.5Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set ...
CVE-2026-5959HIGH7.5A security flaw has been discovered in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1. Affected by this issue is ...
CVE-2026-5444HIGH7.1A heap buffer overflow vulnerability exists in the PAM image parsing logic. When Orthanc processes a crafted PAM image e...
CVE-2026-5441HIGH7.1An out-of-bounds read vulnerability exists in the `DecodePsmctRle1` function of `DicomImageDecoder.cpp`. The `PMSCT_RLE1...
CVE-2026-5440HIGH7.5A memory exhaustion vulnerability exists in the HTTP server due to unbounded use of the `Content-Length` header. The se...
CVE-2026-5439HIGH7.5A memory exhaustion vulnerability exists in ZIP archive processing. Orthanc automatically extracts ZIP archives uploaded...
CVE-2026-5438HIGH7.5A gzip decompression bomb vulnerability exists when Orthanc processes HTTP request with `Content-Encoding: gzip`. The se...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now