2026 CVE Vulnerabilities

43,288 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-14996HIGH8.2IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.
CVE-2026-14981HIGH7.5IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 a...
CVE-2026-14959HIGH7.2IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to ...
CVE-2026-14958HIGH7.2IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 could allow a remote authenticated attacker to execute arbitrary code due to ...
CVE-2026-14893HIGH7.3IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core ...
CVE-2026-14528HIGH7.5IBM WebSphere Application Server 9.0, and 8.5 traditional could allow a remote attacker to obtain sensitive information.
CVE-2026-13463HIGH7.5IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of creden...
CVE-2026-13442HIGH7.1IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only...
CVE-2026-57510HIGH8.8SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers t...
CVE-2026-55555HIGH7.5Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack thr...
CVE-2026-55554HIGH7.5Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot bo...
CVE-2026-48060HIGH8.1Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which...
CVE-2026-16347HIGH8.8MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessi...
CVE-2026-7769HIGH8.1IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM ...
CVE-2026-66745HIGH7.5Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability t...
CVE-2026-59932HIGH7.5PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 t...
CVE-2026-50738HIGH7.7A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced aft...
CVE-2026-49258HIGH8.8Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*...
CVE-2026-48396HIGH8.6Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the cont...
CVE-2026-48395HIGH8.6Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contex...
CVE-2026-48394HIGH7.8Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ...
CVE-2026-48393HIGH7.8Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ...
CVE-2026-48392HIGH7.8Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context ...
CVE-2026-48391HIGH8.2Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contex...
CVE-2026-48390HIGH8.2Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker co...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now