2026 CVE Vulnerabilities

55,909 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7120MEDIUM5.3@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the ...
CVE-2026-15074HIGH7.5@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the...
CVE-2026-21723MEDIUM5.3The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates ...
CVE-2026-16653MEDIUM5.5A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the ...
CVE-2026-16632HIGH7.3A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the lib...
CVE-2026-16631MEDIUM5.3A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/p...
CVE-2026-61246HIGH8.8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60455HIGH8.8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60439HIGH8.8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60373HIGH8.8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60372CRITICAL9.8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60371HIGH8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60370HIGH7.5Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60369CRITICAL9.9Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60368HIGH8.8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60367CRITICAL9.8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-60366CRITICAL10Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third...
CVE-2026-38766HIGH7.8An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_1...
CVE-2026-38765HIGH7.8An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kerne...
CVE-2026-38763MEDIUM5.5An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the...
CVE-2026-16630MEDIUM5.3A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the funct...
CVE-2026-16629MEDIUM5.3A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the ...
CVE-2026-16628MEDIUM5.3A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec o...
CVE-2026-64798CRITICAL9.1Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also...
CVE-2026-64797HIGH7.5Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now