2026 CVE Vulnerabilities

57,060 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-31309CRITICAL9.8Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows a...
CVE-2026-15168LOW3.3BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows possible information disclosure
CVE-2026-10037HIGH8.8A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by th...
CVE-2026-8472MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19....
CVE-2026-7492MEDIUM5.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.1 before 18.11.7, 19.0 before 19.0.4, and 1...
CVE-2026-6896MEDIUM5.4GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19...
CVE-2026-6352LOW2.7GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.11.7, 19.0 before 19.0.4, and 19....
CVE-2026-60105HIGH8.6Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an...
CVE-2026-59818HIGH8.1etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is con...
CVE-2026-58525HIGH8.2Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature ...
CVE-2026-58494MEDIUM6.5Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1, wasmtime-wasi hard-link creation a...
CVE-2026-58211MEDIUM5.4NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2....
CVE-2026-58208HIGH7.5NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2....
CVE-2026-58207MEDIUM6.5NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2....
CVE-2026-58192CRITICAL10Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior...
CVE-2026-58191MEDIUM6.1Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior...
CVE-2026-57481LOW2.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a...
CVE-2026-57480HIGH8.7Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a...
CVE-2026-56669HIGH7.5Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server commun...
CVE-2026-55778LOW2.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-a...
CVE-2026-55596HIGH8.7Plate is a rich-text editor with AI and shadcn/ui. From 53.0.0 until 53.1.4, the media embed renderer trusts serialized ...
CVE-2026-55542MEDIUM4.3Snipe-IT is an IT asset/license management system. Prior to version 8.6.1, Snipe-IT S3 signature image retrieval lacks a...
CVE-2026-55206HIGH8.7py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio...
CVE-2026-55195HIGH8.7py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio...
CVE-2026-54591HIGH8.1AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now