2026 CVE Vulnerabilities

53,211 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-34791HIGH8.8Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE paramet...
CVE-2026-34790HIGH8.1Endian Firewall version 3.3.25 and prior allow authenticated users to delete arbitrary files via directory traversal in ...
CVE-2026-34728HIGH8.1phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handl...
CVE-2026-33641HIGH7.8Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.3, Glances supports dynamic config...
CVE-2026-33544HIGH7.7Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations ...
CVE-2026-31937HIGH7.5Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a p...
CVE-2026-31935HIGH7.5Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation ...
CVE-2026-31934HIGH7.5Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexi...
CVE-2026-5338HIGH7.2A security vulnerability has been detected in Tenda G103 1.0.0.5. The affected element is the function action_set_system...
CVE-2026-3692HIGH8.8In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may cr...
CVE-2026-35168HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, th...
CVE-2026-31933HIGH7.5Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause S...
CVE-2026-31932HIGH7.5Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can le...
CVE-2026-31931HIGH7.5Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the "tls.alpn" rule ke...
CVE-2026-2701HIGH8.8Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
CVE-2026-29782HIGH7.2OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, th...
CVE-2026-28805HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, mu...
CVE-2026-26928HIGH8.7SzafirHost downloads necessary files in the context of the initiating web page. When called, SzafirHost updates its dyna...
CVE-2026-4636HIGH8.1A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) po...
CVE-2026-4634HIGH7.5A flaw was found in Keycloak. An unauthenticated attacker can exploit this vulnerability by sending a specially crafted ...
CVE-2026-4282HIGH7.4A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace iso...
CVE-2026-3872HIGH7.3A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass...
CVE-2026-23415HIGH7.8In the Linux kernel, the following vulnerability has been resolved: futex: Fix UaF between futex_key_to_node_opt() and ...
CVE-2026-23413HIGH7.8In the Linux kernel, the following vulnerability has been resolved: clsact: Fix use-after-free in init/destroy rollback...
CVE-2026-23412HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netfilter: bpf: defer hook memory release until rcu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now