2026 CVE Vulnerabilities

60,112 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-50765MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Man...
CVE-2026-49984HIGH7.7Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage ba...
CVE-2026-49869CRITICAL10Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestr...
CVE-2026-45807HIGH7.7Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 and 1.3.19, several Kestra API endpoints ...
CVE-2026-38571MEDIUM4.6Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, ...
CVE-2026-36908MEDIUM5.5A stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity component of axiomatic-systems Bento4 before v1.8...
CVE-2026-36907MEDIUM5.5A stack overflow in the AP4_StsdAtom::AP4_StsdAtom component of axiomatic-systems Bento4 before v1.8.9allows attackers t...
CVE-2026-36478HIGH7.5An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsSer...
CVE-2026-54353HIGH7.1Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypas...
CVE-2026-54352CRITICAL9.6Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/ro...
CVE-2026-54351CRITICAL9.6Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly acce...
CVE-2026-54350CRITICAL9.8Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase ap...
CVE-2026-52885MEDIUM6.3Notepad++ is a free and open-source source code editor. Prior to 8.9.6.4, NppCommands.cpp checks the HMAC of the on-disk...
CVE-2026-52884HIGH7.8Notepad++ is a free and open-source source code editor. In v8.9.6.1, isInTrustedDirectory() does NOT canonicalize the pa...
CVE-2026-50137CRITICAL9.4Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a worksp...
CVE-2026-50136MEDIUM5.3Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoin...
CVE-2026-50132HIGH7.3Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a publi...
CVE-2026-48800HIGH7.8Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <Command> tag text content inside <UserDef...
CVE-2026-48778HIGH7.8Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <GUIConfig name="commandLineInterpreter"> ...
CVE-2026-48770MEDIUM5Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, a local process in the same interactive Window...
CVE-2026-46710HIGH7.8Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege esc...
CVE-2026-46604HIGH7.5The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.
CVE-2026-39031MEDIUM5.5Lansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded 142-byte static key array to encrypt crede...
CVE-2026-38641HIGH7.5An issue in the DSO::mmap_and_copy function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) ...
CVE-2026-38639HIGH7.5An issue in the parse_month function (/time/strptime.rs) of relibc commit ab6a2e allows attackers to cause a Denial of S...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now