2026 CVE Vulnerabilities

56,994 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15692HIGH8.8A weakness has been identified in Tenda BE12 Pro 16.03.66.23. This vulnerability affects the function fromSafeUrlFilter ...
CVE-2026-15691HIGH8.8A security flaw has been discovered in Tenda BE12 Pro 16.03.66.23. This affects the function fromSafeClientFilter of the...
CVE-2026-15305MEDIUM6.3Users were able to upload files with arbitrary MIME types to forms using FileUpload or ImageUpload elements with allowed...
CVE-2026-12588MEDIUM6An attacker with access to an HX 10.0.0  and previous versions, may send specially-crafted data to the HX console. The m...
CVE-2026-10577CRITICAL10A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible deb...
CVE-2026-9341MEDIUM4.3The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Di...
CVE-2026-15690LOW3.1A vulnerability was identified in open62541 up to 1.5.5. Affected by this issue is the function responseReadNamespacesAr...
CVE-2026-62422CRITICAL9.8In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 aut...
CVE-2026-15389HIGH8.7A vulnerability relating to insufficient access control has been identified in the session management of the Sesame Time...
CVE-2026-58319CRITICAL9.1Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated ...
CVE-2026-56451CRITICAL10A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate...
CVE-2026-54429HIGH7.4A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All versions). Affected devices do not properly handl...
CVE-2026-3014CRITICAL9.1Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerabilit...
CVE-2026-15043CRITICAL9.8DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, ...
CVE-2026-14852MEDIUM5.2Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (...
CVE-2026-12478MEDIUM4.8The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the integer overflow guard inside the if (masked) block...
CVE-2026-9561HIGH8.2Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source o...
CVE-2026-8384MEDIUM5.3In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: ...
CVE-2026-6790MEDIUM5.3In Eclipse Jetty, for HTTP/1, HTTP/2 and HTTP/3 requests, there is no strict check that the request authority (host and ...
CVE-2026-59246MEDIUM6.3Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP/2 server to exhaust memory...
CVE-2026-59084CRITICAL9.1Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the Enc...
CVE-2026-59083CRITICAL9.1Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constra...
CVE-2026-58229HIGH8.2Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory o...
CVE-2026-57898CRITICAL9In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backen...
CVE-2026-15416HIGH8.9A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticate...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now