2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-63096MEDIUM6.9Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to ca...
CVE-2026-63095HIGH7.1Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any...
CVE-2026-60025HIGH8.8Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking p...
CVE-2026-60024CRITICAL9.8Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Event...
CVE-2026-58149MEDIUM5.3Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking i...
CVE-2026-58148HIGH8.7Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension...
CVE-2026-15783MEDIUM5.3A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with...
CVE-2026-15343HIGH8.6A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code executio...
CVE-2026-15007MEDIUM5.7A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause...
CVE-2026-14871HIGH7.1osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Obje...
CVE-2026-14741HIGH7.5HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date. parse_da...
CVE-2026-12715HIGH8.5Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an at...
CVE-2026-63094HIGH8.1SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated...
CVE-2026-63093HIGH8.8Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbit...
CVE-2026-51083MEDIUM6.5Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows u...
CVE-2026-51082HIGH7.2A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager be...
CVE-2026-51081MEDIUM6.1A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environmen...
CVE-2026-16089MEDIUM5.9A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 aut...
CVE-2026-16017MEDIUM6.3A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file to...
CVE-2026-12705MEDIUM6.4Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue a...
CVE-2026-9592HIGH7.5SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user sess...
CVE-2026-7488HIGH7.5Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embed...
CVE-2026-51080CRITICAL9.8libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnera...
CVE-2026-16072MEDIUM4.9A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to mana...
CVE-2026-16016HIGH7.3A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function run_task of the file ex...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now