2026 CVE Vulnerabilities

64,909 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-90601HIGH7.3A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_serv...
CVE-2026-15891HIGH7.5The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after...
CVE-2026-90593HIGH7.3A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of t...
CVE-2026-88802HIGH7.5The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3...
CVE-2026-88793HIGH8.8The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions...
CVE-2026-85129HIGH8.8The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import featu...
CVE-2026-74933HIGH8.8The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJA...
CVE-2026-37008HIGH8.1CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vu...
CVE-2026-36453HIGH7.4Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra ...
CVE-2026-29811HIGH7.7CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a pr...
CVE-2026-90579HIGH7.3A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http...
CVE-2026-90566HIGH7.3A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. A...
CVE-2026-90526HIGH7.3A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unk...
CVE-2026-90524HIGH7.3A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d30995...
CVE-2026-90523HIGH7.3A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af0...
CVE-2026-90783HIGH7.8MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to i...
CVE-2026-90522HIGH7.3A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938...
CVE-2026-90780HIGH7.5SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when proc...
CVE-2026-90779HIGH7.5SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authenticati...
CVE-2026-90778HIGH7.5SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers wi...
CVE-2026-90777HIGH8.8ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitr...
CVE-2026-90776HIGH7.5Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser componen...
CVE-2026-90516HIGH7.3A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown f...
CVE-2026-90515HIGH7.3A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unkn...
CVE-2026-90774HIGH7.5rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now