2026 CVE Vulnerabilities

64,788 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-77409HIGH8.2RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.dispatch in channel.go, confirms.confirm in conf...
CVE-2026-77407HIGH7RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as ...
CVE-2026-77406HIGH8.2RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.Qos in channel.go accepts negative prefetchCount...
CVE-2026-77404HIGH8.7RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.String in uri.go concatenates CertFile, KeyFile, CAC...
CVE-2026-77403HIGH8.9RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-ad...
CVE-2026-76825HIGH8.4RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted en...
CVE-2026-76163HIGH7.5If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of ...
CVE-2026-74909HIGH8.1Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security p...
CVE-2026-63671HIGH8.1MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nu...
CVE-2026-63128HIGH7.5RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP s...
CVE-2026-63127HIGH8.2RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in cr...
CVE-2026-19666HIGH7.5On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a speci...
CVE-2026-18212HIGH7.5A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management ...
CVE-2026-92469HIGH8.1zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DE...
CVE-2026-92467HIGH8.3zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/pass...
CVE-2026-92466HIGH8.8zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth....
CVE-2026-92362HIGH7.3A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-clie...
CVE-2026-92137HIGH8.8Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framewor...
CVE-2026-92136HIGH8Jenkins OWASP Dependency-Check Plugin 5.6.4 and earlier does not escape CWE values from Dependency-Check reports on the ...
CVE-2026-92135HIGH8Jenkins Coverage Plugin 3.3358.v9487dde48783 and earlier does not validate the coverage results ID when a job configurat...
CVE-2026-92134HIGH8Jenkins Warnings Plugin 13.10258.va_17d49a_78c3b_ and earlier does not validate the analysis results ID when a job confi...
CVE-2026-92129HIGH7.5Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods ...
CVE-2026-92128HIGH7.5Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming...
CVE-2026-92127HIGH8Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item...
CVE-2026-92126HIGH8.5Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject @Builder annotations whose builderStrat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now