2026 CVE Vulnerabilities

57,021 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-55780LOW2.4NanaZip is the 7-Zip derivative intended for the modern Windows experience. Prior to 6.5.1749.0, NanaZip's .NET single-f...
CVE-2026-55687HIGH7.5ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. Versions 6.0.1, 5.5.4, 5.4.4, 5.3.5, and possib...
CVE-2026-55669MEDIUM4.2ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Prov...
CVE-2026-55641HIGH8.29Router is an AI router & token saver. Prior to 0.5.2, 9router determines whether a /v1 LLM proxy request is local by re...
CVE-2026-55638HIGH8.69Router is an AI router & token saver. Prior to 0.5.2, 9router protects /v1, /v1beta, /api/v1, and /api/v1beta in src/da...
CVE-2026-54919HIGH7.4cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. In affected Mbed TLS backend versions ...
CVE-2026-54063HIGH7.5Excelize is a Go language library for reading and writing Microsoft Excel spreadsheets. Prior to 2.11.0, the checkSheet(...
CVE-2026-53657HIGH8.2Lima launches Linux virtual machines, typically on macOS, for running containerd. Prior to 2.1.3, on an instance of Lima...
CVE-2026-53653HIGH8.7Grav is a file-based Web platform. Prior to 1.7.53 and 2.0.0-rc.8, Grav allows an unauthenticated visitor to exhaust ser...
CVE-2026-51119CRITICAL9.1An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser co...
CVE-2026-3251MEDIUM6.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webremium Istanbul...
CVE-2026-39903HIGH7.1Simple Machines Forum 2.1 prior to commit 7d048f8 and 3.0 prior to commit a7875e8 contains an authorization bypass vulne...
CVE-2026-39244HIGH7.5adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size hea...
CVE-2026-2398HIGH8.8Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privil...
CVE-2026-1667HIGH7.2The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scrip...
CVE-2026-15377MEDIUM4.3A vulnerability was determined in Eleveo Call Recording Software 9.7.0. Affected by this vulnerability is an unknown fun...
CVE-2026-15376MEDIUM6.3A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/...
CVE-2026-8609HIGH7.5An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory...
CVE-2026-8595MEDIUM5.4A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that ex...
CVE-2026-56676HIGH7.49Router is an AI router & token saver. Prior to 0.5.2, 9router validates image URLs by resolving the host before fetchin...
CVE-2026-55501HIGH7.39Router is an AI router & token saver. Prior to 0.4.80, the dashboard login rate limiter in src/lib/auth/loginLimiter.js...
CVE-2026-55500CRITICAL9.99Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export ...
CVE-2026-54149HIGH8.8MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.0-lts, MaxKB tool import functionality in apps/tools/...
CVE-2026-54001HIGH7osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Wind...
CVE-2026-54000HIGH7osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Wind...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now