2026 CVE Vulnerabilities

66,321 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-71540HIGH7.5Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. F...
CVE-2026-63645HIGH7.5OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoin...
CVE-2026-61816HIGH7.5zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading mess...
CVE-2026-61815HIGH7.2zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading mess...
CVE-2026-61811MEDIUM6.5Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. F...
CVE-2026-61788HIGH7.4DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to version 0.22.6, settin...
CVE-2026-61784MEDIUM6.1xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML. Ve...
CVE-2026-61782HIGH7.5Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsdoctor repo...
CVE-2026-61742CRITICAL9.3DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose...
CVE-2026-61741CRITICAL9.3http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions ...
CVE-2026-61732CRITICAL10Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of...
CVE-2026-61604CRITICAL9.3The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds mo...
CVE-2026-57179MEDIUM4.2Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resum...
CVE-2026-57178HIGH7.4Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accep...
CVE-2026-57177MEDIUM4.3Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend di...
CVE-2026-57176MEDIUM6.8Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend us...
CVE-2026-57175MEDIUM6.4Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted ...
CVE-2026-54461MEDIUM6.5Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query p...
CVE-2026-97521——In the Linux kernel, the following vulnerability has been resolved: gfs2: fix quota init duplicate scan gfs2_quota_ini...
CVE-2026-97520HIGH7.1In the Linux kernel, the following vulnerability has been resolved: gfs2: move quota_init qc iterator increment Move q...
CVE-2026-97519——In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix null pointer dereference in devcoredump...
CVE-2026-97518——In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: reject duplicate wiphy cipher suite...
CVE-2026-97517——In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject beacons with bad HE operation...
CVE-2026-97516——In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Add NULL check for chip->edcca_th in r...
CVE-2026-97515——In the Linux kernel, the following vulnerability has been resolved: i3c: master: svc: Prevent IRQ storm from false SLVS...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now