2026 CVE Vulnerabilities

56,898 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-64881HIGH8.8The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command exe...
CVE-2026-64822MEDIUM6.9djangoSIGE through 1.10 (commit a6fe7e8) contains a user enumeration vulnerability in ForgotPasswordView within djangosi...
CVE-2026-64821MEDIUM5.3djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated...
CVE-2026-63764HIGH8.6LMDeploy through 0.14.0, fixed in commit 03c3130, contains a server-side request forgery (SSRF) vulnerability in the _lo...
CVE-2026-63358HIGH8.4FileGator accepts arbitrary Unix permission values via the '/chmoditems' API endpoint and passes the value directly to P...
CVE-2026-63140MEDIUM6.5Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A ...
CVE-2026-63139MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)...
CVE-2026-63136MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP...
CVE-2026-63092MEDIUM5.3kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any a...
CVE-2026-63080HIGH7.1Aptabase through commit 5a89368 contains a SQL injection vulnerability in the ClickHouse query backend that allows authe...
CVE-2026-56147HIGH7.1Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized information disclosure and...
CVE-2026-52476HIGH7.5SQL Injection vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the getPage...
CVE-2026-52475MEDIUM6.1Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the ...
CVE-2026-52474HIGH7.5An issue in aiflowy <= 2.1.2 allows a remote attacker to obtain sensitive information via the JobUtil.java file.
CVE-2026-52472CRITICAL9.8SQL injection vulnerability in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the PortInfoMapper.xml ...
CVE-2026-52470CRITICAL9.8SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the RecordStateMapper...
CVE-2026-52469CRITICAL9.8SQL injection vulnerability in Crocus v.1.3.44 allows a remote attacker to escalate privileges via the DeviceInfoMapper....
CVE-2026-47714MEDIUM6.1libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code i...
CVE-2026-47708CRITICAL9.3MCP-for-Stata is an MCP server for Stata to integrate Stata into an agent. Prior to version 1.17.3, the `log_file_name` ...
CVE-2026-47697HIGH7.1Shelf is a platform for tracking physical assets. Shelf is multi-tenant; data is isolated per organization (workspace). ...
CVE-2026-47695HIGH7.1CC: Tweaked is a mod for Minecraft which adds programmable computers, turtles, and more to the game. Prior to version 1....
CVE-2026-47690HIGH7.5MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to ...
CVE-2026-47689MEDIUM5.2FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1....
CVE-2026-47688HIGH8.2FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1....
CVE-2026-47687HIGH8.7FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now