2026 CVE Vulnerabilities

56,949 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-50163HIGH7.1oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 vali...
CVE-2026-50162MEDIUM6.9oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a le...
CVE-2026-50151HIGH7.5oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completeP...
CVE-2026-4942HIGH7.5IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Tran...
CVE-2026-4938MEDIUM6.5IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident...
CVE-2026-49852HIGH8.7joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar...
CVE-2026-49834HIGH7.5sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransp...
CVE-2026-49284HIGH7.1SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7 and 2.5.2, SimpleSA...
CVE-2026-48978LOW2.1oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's ...
CVE-2026-48819MEDIUM4.8Hey API is an ecosystem for turning API specifications into production-ready code. Prior to 0.97.3, dist/clients/core/pa...
CVE-2026-48504MEDIUM5.3OpenTelemetry Rust is the Rust OpenTelemetry implementation. In 0.32.0 and earlier, BaggagePropagator::extract_with_cont...
CVE-2026-48373HIGH7.8Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution i...
CVE-2026-46420CRITICAL9.8setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.2...
CVE-2026-45799HIGH7.5Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArra...
CVE-2026-45704HIGH7.1Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, CustomReports uses i...
CVE-2026-45260HIGH8.1Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, Pimcore's WebDAV ass...
CVE-2026-44974HIGH7.7@hapi/content provided HTTP Content-* headers parsing. Prior to 6.0.2, Content.disposition() retained the last occurrenc...
CVE-2026-44739HIGH8.7Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.6, the columnConfigActi...
CVE-2026-43636Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-42168CRITICAL9.1django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner ...
CVE-2026-36669CRITICAL9.8An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote ...
CVE-2026-16118HIGH7.1A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the ...
CVE-2026-15995MEDIUM4.2IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain inc...
CVE-2026-15415MEDIUM6.8AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure ...
CVE-2026-15322HIGH7.5IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now