2026 CVE Vulnerabilities

55,151 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12502HIGH8.4Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, ...
CVE-2026-12496HIGH8.7Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-I...
CVE-2026-17048MEDIUM4.9A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs w...
CVE-2026-9765HIGH7.1Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are ...
CVE-2026-7484MEDIUM5.3External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Fu...
CVE-2026-66144HIGH7.5Although remote policy references are not retrieved during policy normalization, if they are manually retrieved via the ...
CVE-2026-66143HIGH7.5It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2...
CVE-2026-66142HIGH7.5Apache Neethi is vulnerable to uncontrolled recursion when parsing policies that lack policy Ids or with deeply nested s...
CVE-2026-66010MEDIUM6.1DOMPurify before 3.4.12 fails to execute afterSanitizeElements hook for custom elements allowed via CUSTOM_ELEMENT_HANDL...
CVE-2026-66009MEDIUM6.3Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages...
CVE-2026-66008MEDIUM6.3Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target cla...
CVE-2026-46452MEDIUM5.3Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken dat...
CVE-2026-45816HIGH7.5NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asser...
CVE-2026-45815HIGH7.5Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_...
CVE-2026-45813HIGH8.8Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper valida...
CVE-2026-45812MEDIUM6.5Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event....
CVE-2026-45811HIGH7.5Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket tr...
CVE-2026-16743MEDIUM5.5A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root ...
CVE-2026-16730MEDIUM5.5A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer set...
CVE-2026-15810HIGH8.7A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.6...
CVE-2026-15243HIGH7.4Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches th...
CVE-2026-10610HIGH8.5Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.
CVE-2026-7483HIGH8.5Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a...
CVE-2026-16634CRITICAL9.8TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is ...
CVE-2026-15663MEDIUM4.9The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injecti...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now