2026 CVE Vulnerabilities

64,788 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-92125HIGH8.8Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annot...
CVE-2026-92124HIGH8.8Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elem...
CVE-2026-92123HIGH8.8Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null recei...
CVE-2026-92122HIGH8.8Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy crea...
CVE-2026-89028HIGH7.5MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows re...
CVE-2026-81736HIGH7.5If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the...
CVE-2026-81563HIGH7.5A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fa...
CVE-2026-77692HIGH7.5An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(...
CVE-2026-73177HIGH8.6Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware ...
CVE-2026-61598HIGH7.1djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ...
CVE-2026-61590HIGH7.4djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ...
CVE-2026-19667HIGH7.5If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in...
CVE-2026-88817HIGH8.7An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an exi...
CVE-2026-73176HIGH8.6Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2026-73175HIGH7.1Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway compone...
CVE-2026-73174HIGH8.7Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserve...
CVE-2026-73173HIGH8.8Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver m...
CVE-2026-73171HIGH8.6Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore work...
CVE-2026-73170HIGH8.6Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the...
CVE-2026-73167HIGH8.6Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2026-73166HIGH8.6Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the...
CVE-2026-73165HIGH8.6Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2026-73164HIGH8.6Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2026-73163HIGH8.6Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2026-19535HIGH8.6Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative we...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now