2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-50012MEDIUM5.5Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handli...
CVE-2026-47751MEDIUM5.3Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests and issues. Prior to...
CVE-2026-47729MEDIUM6.5Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in t...
CVE-2026-46621CRITICAL9.1Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamica...
CVE-2026-46562CRITICAL9.8Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScrip...
CVE-2026-45795MEDIUM5.3The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server ac...
CVE-2026-45612MEDIUM5.5rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can...
CVE-2026-45576HIGH7.5zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores at...
CVE-2026-45568CRITICAL9.1zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Fl...
CVE-2026-45367HIGH7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7,...
CVE-2026-45325HIGH8.2Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade...
CVE-2026-44632CRITICAL9.1Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs a...
CVE-2026-44596CRITICAL9.8Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handl...
CVE-2026-44595MEDIUM4.3Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGrou...
CVE-2026-3031CRITICAL9.8Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg...
CVE-2026-14371HIGH8.8The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vul...
CVE-2026-13401HIGH7.5XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_p...
CVE-2026-13397HIGH7.5HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_...
CVE-2026-13104HIGH7.3A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could al...
CVE-2026-13103HIGH7.3A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market...
CVE-2026-10590MEDIUM6.7A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrar...
CVE-2026-10589MEDIUM6.8A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Manageme...
CVE-2026-10588MEDIUM6.7A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management...
CVE-2026-10587MEDIUM6.8A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management setting...
CVE-2026-63082MEDIUM5.4Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now