2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54728MEDIUM6.1bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb ...
CVE-2026-49998HIGH8.2Centrifugo is an open-source scalable real-time messaging server. Prior to 6.8.1, Centrifugo dynamic JWKS endpoint verif...
CVE-2026-44982HIGH7.2CrowdSec offers crowdsourced protection against malicious IPs. From 1.5.0 until 1.7.8, pkg/appsec/request.go NewParsedRe...
CVE-2026-44981HIGH8.2CrowdSec offers crowdsourced protection against malicious IPs. From 1.7.0 until 1.7.8, the LAPI router used gin-contrib/...
CVE-2026-15449MEDIUM5.8A time-of-check to time-of-use (TOCTOU) flaw in the illumos data-link pseudo-driver (dld) affects handling of the DLDIOC...
CVE-2026-15422CRITICAL9.1The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address ...
CVE-2026-15352HIGH8.2A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the a...
CVE-2026-54526CRITICAL9.9Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t...
CVE-2026-53536MEDIUM5.3Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /v1/step-files/signed download endp...
CVE-2026-53535MEDIUM5.9Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-conf...
CVE-2026-47089MEDIUM4.3An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin acces...
CVE-2026-47088LOW3.1An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsi...
CVE-2026-47087LOW3.5An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A...
CVE-2026-47086LOW3.5An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authe...
CVE-2026-47085MEDIUM4An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxk...
CVE-2026-47084MEDIUM6.5An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An aut...
CVE-2026-47083MEDIUM4.3An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By u...
CVE-2026-47082MEDIUM5.4An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-ma...
CVE-2026-47081LOW3.1An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence orac...
CVE-2026-46515CRITICAL9.3Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call ...
CVE-2026-46514MEDIUM6.5Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_reset_password in Tools/ResetPassword...
CVE-2026-46513HIGH7.4Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, Frogman stored API tokens generated by T...
CVE-2026-46512CRITICAL9.9Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template para...
CVE-2026-46404MEDIUM6.8BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly res...
CVE-2026-46378MEDIUM6.2Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now