2026 CVE Vulnerabilities

56,998 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40553HIGH7.5Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue...
CVE-2026-40469CRITICAL9.1Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could b...
CVE-2026-40468CRITICAL9.1Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaust...
CVE-2026-40467HIGH7.5Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may ...
CVE-2026-15584HIGH7.5A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. The tool creates privileged d...
CVE-2026-15559MEDIUM6.3A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the...
CVE-2026-62147MEDIUM6.5The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API respons...
CVE-2026-15558MEDIUM6.3A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issu...
CVE-2026-12257CRITICAL9.3Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located...
CVE-2026-9824MEDIUM4.3Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels per...
CVE-2026-9820LOW3.8Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams end...
CVE-2026-6541MEDIUM4.3Mattermost versions 11.7.x <= 11.7.1, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict metric configuration change...
CVE-2026-4765NONE0Self Cross-Site Scripting (Self-XSS) vulnerability in the RD Station Conversas chat feature. The vulnerability lies in t...
CVE-2026-14934CRITICAL9.4A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Co...
CVE-2026-61985MEDIUM5.3Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectl...
CVE-2026-61983MEDIUM5.3Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Acc...
CVE-2026-61977MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetSearch jet-sea...
CVE-2026-61976MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetBlocks For Ele...
CVE-2026-61975MEDIUM5.3Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Crocoblock JetReviews jet-re...
CVE-2026-61971LOW2.7Authorization Bypass Through User-Controlled Key vulnerability in Cozmoslabs User Profile Picture metronet-profile-pictu...
CVE-2026-61970MEDIUM4.9Server-Side Request Forgery (SSRF) vulnerability in Themeisle Auto Featured Image (Auto Post Thumbnail) auto-post-thumbn...
CVE-2026-61968MEDIUM5.4Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control ...
CVE-2026-61958MEDIUM5.4Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows...
CVE-2026-61956HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in hamsalam ووسلام &#8211; همگام سازی ووکامرس و باسلام sync-basalam allo...
CVE-2026-61955HIGH7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Hannan گرویتی فرم ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now