2026 CVE Vulnerabilities

65,293 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-102005MEDIUM5.5Wind River VxWorks 7 24.03 through 26.03, a memory leak occurs under specific, non-default configuration states when pro...
CVE-2026-101918MEDIUM5.3PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_k...
CVE-2026-101917MEDIUM5.3PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT get_signing_key_from_jwt is affecte...
CVE-2026-101916HIGH7.4@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1...
CVE-2026-101187CRITICAL9.1A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function pop_usb_device of ...
CVE-2026-101146MEDIUM4.3A security flaw has been discovered in Eleveo Quality Management 9.7.0. This issue affects the function UtilsService.cre...
CVE-2026-101145MEDIUM4.3A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the f...
CVE-2026-101144MEDIUM6.3A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callre...
CVE-2026-100392HIGH7InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Us...
CVE-2026-100371HIGH8.7InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, an...
CVE-2026-100370MEDIUM4.7DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is respons...
CVE-2026-96760——Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json...
CVE-2026-93355HIGH8.1LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured ide...
CVE-2026-87741HIGH8.8The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and inclu...
CVE-2026-86950HIGH8.8An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 2...
CVE-2026-102004HIGH7.8Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory ma...
CVE-2026-101915LOW3.7@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1...
CVE-2026-101914MEDIUM6.5@grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1...
CVE-2026-101143MEDIUM4.3A vulnerability was found in Eleveo Quality Management 9.7.0. Affected by this issue is some unknown functionality of th...
CVE-2026-101142MEDIUM6.3A vulnerability has been found in Eleveo Quality Management 9.7.0. Affected by this vulnerability is an unknown function...
CVE-2026-101141LOW3.5A flaw has been found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/audi...
CVE-2026-97686MEDIUM5.5Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properl...
CVE-2026-97023HIGH7.1A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a maliciou...
CVE-2026-84894——In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a F...
CVE-2026-13018MEDIUM4.3Insufficient validation of untrusted input in Codecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now