2026 CVE Vulnerabilities

56,998 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-59083CRITICAL9.1Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constra...
CVE-2026-58229HIGH8.2Allocation of resources without limits vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory o...
CVE-2026-57898CRITICAL9In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backen...
CVE-2026-15416HIGH8.9A flaw was identified in Argo CD, the GitOps engine used by Red Hat OpenShift GitOps, that could allow an unauthenticate...
CVE-2026-15183CRITICAL9.2Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can...
CVE-2026-15076HIGH7.5In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Ve...
CVE-2026-15075HIGH7.5In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx...
CVE-2026-13699MEDIUM6.5In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existenc...
CVE-2026-12606MEDIUM5.3Eclipse Grizzly in versions before 5.0.2, cannot properly parse the trailer section in malformed trailer header's line, ...
CVE-2026-10051HIGH7.5In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests...
CVE-2026-6851HIGH7An Improper link resolution before file access ('link following') vulnerability in the File Shredder module as used in B...
CVE-2026-59674HIGH7.1A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user ...
CVE-2026-15678LOW3.5A security vulnerability has been detected in code-projects Online Job Portal 1.0. This impacts an unknown function of t...
CVE-2026-15677HIGH7.3A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /Job...
CVE-2026-15676HIGH7.3A security flaw has been discovered in code-projects Online Job Portal up to 1.0. The impacted element is an unknown fun...
CVE-2026-15675HIGH7.3A vulnerability was identified in code-projects Online Job Portal 1.0. The affected element is an unknown function of th...
CVE-2026-15672MEDIUM6.3A vulnerability was determined in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the fil...
CVE-2026-15669MEDIUM5.3A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.Execute of the file ...
CVE-2026-12988MEDIUM6.4The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentica...
CVE-2026-12583HIGH8.1The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through ...
CVE-2026-12511HIGH8.1The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downl...
CVE-2026-12482MEDIUM6.5A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the...
CVE-2026-11567MEDIUM5.9The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms that use a dynamica...
CVE-2026-11563CRITICAL9.6The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletio...
CVE-2026-15668MEDIUM6.3A vulnerability has been found in louisho5 picobot up to 0.2.0. This vulnerability affects the function WebTool.Execute ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now