2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49212HIGH7.5Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\Liv...
CVE-2026-49211HIGH7.5Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, Symfony\UX\Autocomplete\Doctrine\En...
CVE-2026-49210MEDIUM6.1Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\Child...
CVE-2026-49209MEDIUM6.5Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller...
CVE-2026-49208MEDIUM5.3Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as Date...
CVE-2026-44722MEDIUM6.2pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python...
CVE-2026-21764MEDIUM4.3HCL DevOps Loop is affected by insufficient input validation that allows special characters where they should be restric...
CVE-2026-21762MEDIUM5.3HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections ag...
CVE-2026-21761MEDIUM5.4HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may ...
CVE-2026-21760MEDIUM4.6HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper a...
CVE-2026-16108MEDIUM6.5A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible...
CVE-2026-16106MEDIUM4.9A flaw was found in the admin REST API of Keycloak, a solution for identity and access management. The issue occurs when...
CVE-2026-16104MEDIUM6.5A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engi...
CVE-2026-16103MEDIUM4.3A flaw was found in the keycloak-services component of Keycloak. This issue is an incomplete fix for CVE-2026-9798, wher...
CVE-2026-16093MEDIUM5.4Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them...
CVE-2026-12694CRITICAL9.1Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Proper...
CVE-2026-12693CRITICAL9.4Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessi...
CVE-2026-12692CRITICAL9.8Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This ...
CVE-2026-12691HIGH7.5Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authenticat...
CVE-2026-11763MEDIUM6.5Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D ...
CVE-2026-9537MEDIUM5.3Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode()...
CVE-2026-63100HIGH7.1Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role u...
CVE-2026-63099HIGH7.1TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints t...
CVE-2026-63098MEDIUM6.9TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated atta...
CVE-2026-63097MEDIUM5.3Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/rout...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now