2026 CVE Vulnerabilities

53,576 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-30707HIGH8.1An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control v...
CVE-2026-25936HIGH8.8GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an auth...
CVE-2026-25790HIGH7.2Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 ...
CVE-2026-25772HIGH7.2Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 ...
CVE-2026-25771HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.3.0 ...
CVE-2026-22882HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2026-20726HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2026-32296HIGH8.8Sipeed NanoKVM before 2.3.1 exposes a Wi-Fi configuration endpoint without proper security checks, allowing an unauthent...
CVE-2026-32294HIGH7JetKVM prior to 0.5.4 does not verify the authenticity of downloaded firmware files. An attacker-in-the-middle or a comp...
CVE-2026-32291HIGH7The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requ...
CVE-2026-32290HIGH7The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware f...
CVE-2026-25770HIGH7.2Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 ...
CVE-2026-21570HIGH8.8This High severity RCE (Remote Code Execution)  vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, ...
CVE-2026-4148HIGH8.8A use-after-free vulnerability can be triggered in sharded clusters by an authenticated user with the read role who issu...
CVE-2026-24901HIGH8.8Outline is a service that allows for collaborative documentation. Prior to 1.4.0, an Insecure Direct Object Reference (I...
CVE-2026-23759HIGH8.6Perle IOLAN STS/SCS terminal server models with firmware versions prior to 6.0 allow authenticated OS command injection ...
CVE-2026-21886HIGH8.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6....
CVE-2026-4318HIGH8.8A vulnerability was determined in UTT HiPER 810G up to 1.7.7-171114. Affected is the function strcpy of the file /goform...
CVE-2026-3888HIGH7.8Local privilege escalation in snapd on Linux allows local attackers to get root privilege by re-creating snap's private ...
CVE-2026-4271HIGH7.5A flaw was found in libsoup, a library for handling HTTP requests. This vulnerability, known as a Use-After-Free, occurs...
CVE-2026-30911HIGH8.1Apache Airflow versions 3.1.0 through 3.1.7 missing authorization vulnerability in the Execution API's Human-in-the-Loop...
CVE-2026-28779HIGH7.5Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configu...
CVE-2026-4208HIGH8.8The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible M...
CVE-2026-1323HIGH8.8The extension fails to properly define allowed classes used when deserializing transport failure metadata. An attacker m...
CVE-2026-4258HIGH7.7Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to miss...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now