2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-35446HIGH8.6LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project...
CVE-2026-35401HIGH7.5Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, a malicious actor can i...
CVE-2026-34724HIGH7.2Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a server-side template injection vul...
CVE-2026-34723HIGH7.5Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1 and 6.5.4, unauthenticated remote att...
CVE-2026-34392HIGH7.5LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project...
CVE-2026-33350HIGH7.5LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project...
CVE-2026-30818HIGH8An OS command injection vulnerability in the dnsmasq module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent...
CVE-2026-30815HIGH8An OS command injection vulnerability in the OpenVPN module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent...
CVE-2026-30814HIGH8A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attac...
CVE-2026-27806HIGH7.8Fleet is open source device management software. Prior to 4.81.1, the Orbit agent's FileVault disk encryption key rotati...
CVE-2026-33756HIGH7.5Saleor is an e-commerce platform. From 2.0.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, Saleor supports query b...
CVE-2026-33458HIGH7.7Server-Side Request Forgery (CWE-918) in Kibana One Workflow can lead to information disclosure. An authenticated user w...
CVE-2026-32590HIGH8.8A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores interm...
CVE-2026-32589HIGH7.4A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any reposit...
CVE-2026-4837HIGH7.2An eval() injection vulnerability in the Rapid7 Insight Agent beaconing logic for Linux versions could theoretically all...
CVE-2026-4498HIGH7.7Execution with Unnecessary Privileges (CWE-250) in Kibana’s Fleet plugin debug route handlers can lead reading index dat...
CVE-2026-30080HIGH7.5OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported int...
CVE-2026-30075HIGH7.5OpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNASTransport containing Authentic...
CVE-2026-33753HIGH7.5rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an ...
CVE-2026-39408HIGH7.5Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal...
CVE-2026-39393HIGH8.1CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-39389HIGH7.2CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-5795HIGH7.4In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. ...
CVE-2026-5302HIGH8.1CORS misconfiguration in CoolerControl/coolercontrold <4.0.0 allows unauthenticated remote attackers to read data and se...
CVE-2026-27102HIGH7.8Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.6 and versions 9.11.0.0 through 9.13.0.1, contains an incorrect p...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now