2026 CVE Vulnerabilities

53,349 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-33645HIGH8.1Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerabilit...
CVE-2026-33623HIGH7.2PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.4` contai...
CVE-2026-33622HIGH8.8PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.3` throug...
CVE-2026-2100HIGH7.5A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a...
CVE-2026-0966HIGH8.2A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-...
CVE-2026-33632HIGH7.8ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4....
CVE-2026-33631HIGH8.7ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. In versions on the ...
CVE-2026-33529HIGH8.8Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. Prior to version 3.3.2, an authenticated path traver...
CVE-2026-32287HIGH7.5Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU u...
CVE-2026-32286HIGH7.5The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can s...
CVE-2026-32285HIGH7.5The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative...
CVE-2026-32284HIGH7.5The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format cod...
CVE-2026-2436HIGH8.2A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup...
CVE-2026-4926HIGH7.5Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax...
CVE-2026-3121HIGH7.2A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where thi...
CVE-2026-33506HIGH8.8Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versio...
CVE-2026-33505HIGH7.2Ory Keto is am open source authorization server for managing permissions at scale. Prior to version 26.2.0, the GetRelat...
CVE-2026-33491HIGH7.8Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.4, a stack-based...
CVE-2026-33152HIGH7.5Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t...
CVE-2026-33149HIGH8.1Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and ...
CVE-2026-30463HIGH7.7Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php co...
CVE-2026-33504HIGH7.2Ory Hydra is an OAuth 2.0 Server and OpenID Connect Provider. Prior to version 26.2.0, the listOAuth2Clients, listOAuth2...
CVE-2026-33503HIGH7.2Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 26.2.0, the Li...
CVE-2026-33496HIGH8.1ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o...
CVE-2026-33487HIGH7.5goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now