2026 CVE Vulnerabilities

53,734 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-28789HIGH7.5OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.3, an unauthenticated ...
CVE-2026-28342HIGH7.5OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash AP...
CVE-2026-28277HIGH7.2LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ...
CVE-2026-3459HIGH8.1The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due...
CVE-2026-3047HIGH8.8A flaw was found in org.keycloak.broker.saml. When a disabled Security Assertion Markup Language (SAML) client is config...
CVE-2026-3009HIGH8.1A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an...
CVE-2026-29054HIGH7.5Traefik is an HTTP reverse proxy and load balancer. From version 2.11.9 to 2.11.37 and from version 3.1.3 to 3.6.8, ther...
CVE-2026-28287HIGH8.8FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, ...
CVE-2026-28284HIGH8.8FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several aut...
CVE-2026-28210HIGH8.8FreePBX is an open source IP PBX. Prior to versions 16.0.49 and 17.0.7, FreePBX module cdr (Call Data Record) is vulnera...
CVE-2026-28209HIGH7.2FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, ...
CVE-2026-26999HIGH7.5Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerabil...
CVE-2026-26418HIGH7.5Missing authentication and authorization in the web API of Tata Consultancy Services Cognix Recon Client v3.0 allows rem...
CVE-2026-26417HIGH8.1A broken access control vulnerability in the password reset functionality of Tata Consultancy Services Cognix Recon Clie...
CVE-2026-26416HIGH8.8An authorization bypass vulnerability in Tata Consultancy Services Cognix Recon Client v3.0 allows authenticated users t...
CVE-2026-26194HIGH7.3Gogs is an open source self-hosted Git service. Prior to version 0.14.2, there's a security issue in gogs where deleting...
CVE-2026-30798HIGH7.5Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-cl...
CVE-2026-30797HIGH8.1Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, An...
CVE-2026-30796HIGH7.5Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in rustdesk-client R...
CVE-2026-30795HIGH7.5Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Wind...
CVE-2026-30792HIGH8.1A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (St...
CVE-2026-25048HIGH7.5xgrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.32,...
CVE-2026-3598HIGH7.5Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-server-pro RustDesk Server Pro rustdesk-serve...
CVE-2026-30791HIGH7.5Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-client RustDesk Client rustdesk-client on Win...
CVE-2026-27750HIGH7Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerability in the Optimizer component. A privil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now