2026 CVE Vulnerabilities

56,998 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49971MEDIUM6.1Laravel-Mediable before 7.0.0 contains a stored cross-site scripting vulnerability that allows authenticated or anonymou...
CVE-2026-49970HIGH8.8Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the File::sanitizePath() function that allows a...
CVE-2026-49969HIGH7.4Laravel-Mediable before 7.0.0 contains a server-side request forgery vulnerability that allows remote attackers to issue...
CVE-2026-26396HIGH7.5OpenBMB XAgent v1.0.0 and before is vulnerable to path traversal in the file() function in XAgent/XAgentServer/applicati...
CVE-2026-14906MEDIUM5.3Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within t...
CVE-2026-61505MEDIUM6.9Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthentica...
CVE-2026-61504MEDIUM5.4Rejetto HFS 3.0.0 through 3.2.0 does not escape file names in its fallback "basic" web listing, and this listing can be ...
CVE-2026-61503MEDIUM6.9Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the ...
CVE-2026-61502MEDIUM5.1Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its...
CVE-2026-61501MEDIUM6.1Rejetto HFS 3.0.0 through 3.2.0 renders log entries in the administration panel as HTML without sanitization. A remote u...
CVE-2026-61500CRITICAL9.8Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generato...
CVE-2026-61463HIGH8.8Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to m...
CVE-2026-61462CRITICAL9.2mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to re...
CVE-2026-60103MEDIUM6.8Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerability that allows attackers to trigger a crash or rea...
CVE-2026-53365MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix zerocopy completion for multi-skb...
CVE-2026-53364MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix memory leak in hci_le_big_...
CVE-2026-57433CRITICAL9.8Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retr...
CVE-2026-57432HIGH8.4Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S...
CVE-2026-13221CRITICAL9.1Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect re...
CVE-2026-61692Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-61454. Reason: This candidate is a ...
CVE-2026-59245HIGH8.1In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission reso...
CVE-2026-58065HIGH8.1The Apache Airflow Git provider runs its git-over-SSH operations with `StrictHostKeyChecking=no` by default, disabling S...
CVE-2026-6847CRITICAL9.3Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload fu...
CVE-2026-61498CRITICAL9.8Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php en...
CVE-2026-60121CRITICAL9.8Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now