2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-46377MEDIUM6.2Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1...
CVE-2026-46353HIGH8.1BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a...
CVE-2026-46351HIGH8.1BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values wit...
CVE-2026-46338MEDIUM4.3PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx....
CVE-2026-46687HIGH7.7Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-t...
CVE-2026-46686HIGH8.5Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user search module's keyword p...
CVE-2026-46341MEDIUM6.1The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation...
CVE-2026-46336HIGH7.1Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on ...
CVE-2026-45336CRITICAL10HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring ...
CVE-2026-44970MEDIUM4.3dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_call...
CVE-2026-44969LOW3.3dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/...
CVE-2026-44968MEDIUM6.3dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/...
CVE-2026-15945LOW2.7A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin ...
CVE-2026-15737MEDIUM5.7AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on t...
CVE-2026-9046HIGH7.3A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications...
CVE-2026-6511MEDIUM6.8During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart...
CVE-2026-63088HIGH8.6stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-...
CVE-2026-63087CRITICAL9.8Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a...
CVE-2026-63086HIGH8.6text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat...
CVE-2026-63085HIGH8.8Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticate...
CVE-2026-57074CRITICAL9.1XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to ...
CVE-2026-57073CRITICAL9.1HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to...
CVE-2026-55548MEDIUM4.3Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/sr...
CVE-2026-55407MEDIUM6.3Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.8.0, the dec...
CVE-2026-55406MEDIUM5.9Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.7.0, a sound...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now