2026 CVE Vulnerabilities

43,288 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-66748HIGH8.8Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows user...
CVE-2026-61609HIGH7.5Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limite...
CVE-2026-54593HIGH8.1Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2,...
CVE-2026-54545HIGH7.1wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 until 1.4.0, @wakaru/cli sanitizes bundle-controlle...
CVE-2026-47483HIGH8.2NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could c...
CVE-2026-47427HIGH7.5GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server....
CVE-2026-45293HIGH8.6WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0....
CVE-2026-43910HIGH8.2Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. Fro...
CVE-2026-8164HIGH7.3Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desk...
CVE-2026-67178HIGH7.8MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-t...
CVE-2026-66299HIGH7.5Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache To...
CVE-2026-63727HIGH8.8Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in th...
CVE-2026-59878HIGH7.5Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthe...
CVE-2026-7187HIGH8.8Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionalit...
CVE-2026-66920HIGH8.2Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data. The affec...
CVE-2026-66918HIGH8.2Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style.svgIcon property before in...
CVE-2026-65881HIGH7.5Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1...
CVE-2026-62433HIGH7.3Parts of the DM_OP handling code assumes the caller has provided the required number of buffers for the given operation ...
CVE-2026-62432HIGH7.3The EVTCHNOP_expand_array hypercall checks for whether FIFO event channels are enabled, but without holding the correct ...
CVE-2026-62431HIGH7.5The logic to handle periodic Viridian STIMERs performs a division with an unchecked user-controlled divisor value, that ...
CVE-2026-62430HIGH7.5Accesses to the CMOS memory contents are done using an indirect IO port pair. Therefore Xen needs to cache the guest ch...
CVE-2026-62428HIGH7.8When grant-copy operations are processed, the respective grant may or may not already be in use by another operation (a ...
CVE-2026-62427HIGH8.8[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-62426HIGH8.8[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-49332HIGH8.5A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now