2026 CVE Vulnerabilities

64,889 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-89023HIGH8.6ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its RES...
CVE-2026-86830HIGH7.2Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution befor...
CVE-2026-82049HIGH8.4In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives con...
CVE-2026-82035HIGH7.1PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_o...
CVE-2026-77884HIGH7.1Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The...
CVE-2026-91080HIGH7.5webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticate...
CVE-2026-91079HIGH8.5Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing h...
CVE-2026-90946HIGH7.5DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSo...
CVE-2026-90944HIGH8.2Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenti...
CVE-2026-90805HIGH7.3A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Th...
CVE-2026-86836HIGH8.4In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIF...
CVE-2026-85921HIGH8.2Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVE-2026-85892HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-...
CVE-2026-73494HIGH7.4blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0....
CVE-2026-70658HIGH7.4Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#valid...
CVE-2026-57577HIGH8.2DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a rout...
CVE-2026-55253HIGH7.7LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-...
CVE-2026-55091HIGH7.5flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested....
CVE-2026-54567HIGH7.5Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask...
CVE-2026-54182HIGH8.1backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha...
CVE-2026-54180HIGH7.6backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha...
CVE-2026-54178HIGH8.1backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha...
CVE-2026-54175HIGH7.6backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha...
CVE-2026-54087HIGH7.6EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageFie...
CVE-2026-53752HIGH7.5docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now