2026 CVE Vulnerabilities

60,149 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48935LOW3.3A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with ...
CVE-2026-48934MEDIUM4.3A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability ...
CVE-2026-48933HIGH7.5A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2Gi...
CVE-2026-48930CRITICAL9.8A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c...
CVE-2026-48928MEDIUM5.4A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulne...
CVE-2026-48619HIGH7.5A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out...
CVE-2026-48618MEDIUM6.5A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth ...
CVE-2026-48615HIGH7.5A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. Wh...
CVE-2026-13226MEDIUM6.5The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection ...
CVE-2026-9222CRITICAL9.2Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authe...
CVE-2026-9221HIGH8.7The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request si...
CVE-2026-9220HIGH8.7Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and i...
CVE-2026-9219HIGH8.3Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derive...
CVE-2026-43920MEDIUM6.9FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patch...
CVE-2026-13322LOW3.8A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Re...
CVE-2026-13318MEDIUM6.4A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-...
CVE-2026-13218MEDIUM4.2A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a laun...
CVE-2026-13083MEDIUM6.9A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper es...
CVE-2026-12993MEDIUM6.5A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but d...
CVE-2026-40941MEDIUM6.5Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import sign...
CVE-2026-40084MEDIUM6.5Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Tra...
CVE-2026-40083HIGH7.2Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through...
CVE-2026-40082MEDIUM5.4Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regen...
CVE-2026-40080MEDIUM6.1Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Red...
CVE-2026-8720HIGH7.5wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, producing a ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now