2026 CVE Vulnerabilities

56,898 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-42397MEDIUM6.5Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A...
CVE-2026-30632HIGH7.5Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.
CVE-2026-15957HIGH8.7Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface ...
CVE-2026-64877HIGH8.4An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stor...
CVE-2026-63454HIGH7.2An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an ...
CVE-2026-63453HIGH7.2Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerab...
CVE-2026-59142CRITICAL9.1Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and leng...
CVE-2026-59141CRITICAL9.1Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices...
CVE-2026-59140CRITICAL9.1Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the ra...
CVE-2026-59139CRITICAL9.1Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and lengt...
CVE-2026-55084HIGH8.8DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL inje...
CVE-2026-55082HIGH8.7DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. DHIS2 SQL ...
CVE-2026-55081HIGH7.3DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. The DHIS2 ...
CVE-2026-16441CRITICAL9.6In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been...
CVE-2026-12548MEDIUM4.2A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch betw...
CVE-2026-12547LOW3.4SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When th...
CVE-2026-56583LOW3.1HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session h...
CVE-2026-56582LOW3.1HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sen...
CVE-2026-56581LOW2.6HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session ...
CVE-2026-56580LOW2.2HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit ...
CVE-2026-56579LOW3.1HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed infor...
CVE-2026-56578LOW2.2HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities ...
CVE-2026-56577MEDIUM6.5HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force o...
CVE-2026-47657HIGH7.1HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in ...
CVE-2026-47425MEDIUM6.9Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `Entry...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now