2026 CVE Vulnerabilities

66,000 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-97650MEDIUM4.3A vulnerability has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. A...
CVE-2026-97723MEDIUM5.4madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vulnerability in the chat message rendering fu...
CVE-2026-97649MEDIUM4.7A flaw has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected b...
CVE-2026-97648MEDIUM4.3A vulnerability was detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Aff...
CVE-2026-97647MEDIUM5.3A security vulnerability has been detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207c...
CVE-2026-95811MEDIUM6.5Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl...
CVE-2026-97646HIGH7.3A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. T...
CVE-2026-92289CRITICAL9.1Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKC...
CVE-2026-92288CRITICAL9.1Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth...
CVE-2026-85417MEDIUM6.4Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be reco...
CVE-2026-53493MEDIUM6.9containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI...
CVE-2026-85082HIGH8.5Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely sep...
CVE-2026-84283MEDIUM6.8Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-stor...
CVE-2026-97387——Rejected reason: This CVE is a duplicate of another CVE.
CVE-2026-97230CRITICAL9.8IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated U...
CVE-2026-97636MEDIUM6.5Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-co...
CVE-2026-87722HIGH8.7Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search query predicates (such as RegexProjectPredicate, ...
CVE-2026-87721HIGH8.7Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerr...
CVE-2026-87720HIGH7.6Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and ProjectCache eviction l...
CVE-2026-85491HIGH8.8Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorizat...
CVE-2026-97368MEDIUM6.3A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInf...
CVE-2026-97366MEDIUM6.3A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function...
CVE-2026-95699CRITICAL9.6Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT ...
CVE-2026-93353MEDIUM5.3copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users ...
CVE-2026-88388HIGH7.5Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now