2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44182CRITICAL10Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kuber...
CVE-2026-44181CRITICAL10Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kuber...
CVE-2026-43978HIGH8.1wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their sess...
CVE-2026-43977HIGH7.5wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read anoth...
CVE-2026-15997LOW1.7Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc. BC-LTS bcprov-lts8on on ARM allows Overflow Buffer...
CVE-2026-14253Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-11740Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-62826MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2026-59117HIGH7.5Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.
CVE-2026-58643MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an u...
CVE-2026-58598HIGH7Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine all...
CVE-2026-57077HIGH7.7YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len. In t...
CVE-2026-57076HIGH7.8YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key i...
CVE-2026-57075CRITICAL9.1YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64...
CVE-2026-53412CRITICAL9.8Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Wind...
CVE-2026-53411HIGH7A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Cl...
CVE-2026-45368HIGH8.4Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for ...
CVE-2026-45334MEDIUM5.3Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the content-locking feature ret...
CVE-2026-44180CRITICAL9.8Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kuber...
CVE-2026-44177HIGH8.8Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correct...
CVE-2026-44176MEDIUM6Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` per...
CVE-2026-44175HIGH8.5Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize...
CVE-2026-44174HIGH8.7Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes...
CVE-2026-14782MEDIUM4.9The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Cu...
CVE-2026-13713MEDIUM6.2YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now