2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15093MEDIUM4.3IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to redirect users to malicious websites due...
CVE-2026-15091CRITICAL9.3IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary scripts due to imprope...
CVE-2026-15069MEDIUM5.4IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to execute arbitrary script code due to imp...
CVE-2026-14979HIGH7.5IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ...
CVE-2026-14971HIGH7IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attac...
CVE-2026-14501CRITICAL9.8IBM Db2 Genius Hub 1.1, 1.1.1, 1.1.2 and IBM Agentics 1.0 could allow an attacker to execute arbitrary code or obtain se...
CVE-2026-14499HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elev...
CVE-2026-13473CRITICAL9.8IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulner...
CVE-2026-13448CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the...
CVE-2026-12283MEDIUM6.8Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard...
CVE-2026-9171HIGH7.5IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused ...
CVE-2026-9135CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) co...
CVE-2026-9103CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authenti...
CVE-2026-58195HIGH8.8Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone...
CVE-2026-53712HIGH8.2SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security L...
CVE-2026-52746HIGH7.5JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious non-matching inputs to the $toM...
CVE-2026-50185LOW3.3RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-...
CVE-2026-49835HIGH7.5Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middle...
CVE-2026-48487MEDIUM5.3Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string a...
CVE-2026-48045MEDIUM6.5Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.12, AsyncListener.handle_que...
CVE-2026-47184MEDIUM6.5Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.7, DNSCache._async_add inser...
CVE-2026-47183MEDIUM6.5Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.6, DNSIncoming._log_exceptio...
CVE-2026-47180MEDIUM6.5Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.5, DNSIncoming._decode_label...
CVE-2026-45703MEDIUM6.4Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport expor...
CVE-2026-45309HIGH7.5AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now