2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-63081MEDIUM5.4Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability ...
CVE-2026-59867HIGH7.1Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by ...
CVE-2026-59866CRITICAL9.3Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientCl...
CVE-2026-59865CRITICAL9.3Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.lang...
CVE-2026-59864CRITICAL9.3Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin g...
CVE-2026-57206HIGH8.6SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions...
CVE-2026-57205MEDIUM4.3SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions...
CVE-2026-55440MEDIUM6.5Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND...
CVE-2026-54733CRITICAL9.3The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration fo...
CVE-2026-54568MEDIUM4.3Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a c...
CVE-2026-53598HIGH7.5Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:......
CVE-2026-53597HIGH8.7Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prompty/core T...
CVE-2026-45695CRITICAL9.8Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-en...
CVE-2026-14890CRITICAL9.1SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that d...
CVE-2026-12379MEDIUM6.8An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard...
CVE-2026-59863HIGH7Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota honored a poisoned .kiota/worksp...
CVE-2026-59862HIGH7.5Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-...
CVE-2026-59861HIGH7.5Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Ruby generator embedded OpenAP...
CVE-2026-59860HIGH8.7Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.3, Kiota is affected by a code-generation...
CVE-2026-59859HIGH8.7Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.4, Kiota's PHP generator embedded OpenAPI...
CVE-2026-59237MEDIUM6.9Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Pro...
CVE-2026-14254HIGH8.3A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed...
CVE-2026-5674HIGH8.8A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed application...
CVE-2026-56456MEDIUM5.3HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently ...
CVE-2026-56455HIGH7.5HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The applicat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now