2026 CVE Vulnerabilities

44,078 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48078MEDIUM5.3OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48077MEDIUM5.3OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48076MEDIUM6.5OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-clie...
CVE-2026-48075MEDIUM6.5OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48074LOW2.7OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48071MEDIUM5.8OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48054HIGH8.8OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin ...
CVE-2026-47765HIGH7.1Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints ...
CVE-2026-47194HIGH8.6Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation c...
CVE-2026-47185MEDIUM5.1Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspac...
CVE-2026-45573MEDIUM6.4Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-45572MEDIUM4.8Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-45415MEDIUM6Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-45414HIGH8.5Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API auth...
CVE-2026-45378HIGH7.5Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3...
CVE-2026-43632CRITICAL9.2llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six to...
CVE-2026-43631CRITICAL9.2llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-se...
CVE-2026-43630MEDIUM6.5llama.cpp builds b5702 through b7653 contain an out-of-bounds read vulnerability in the recurrent memory state restore p...
CVE-2026-43629CRITICAL9.2llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path whe...
CVE-2026-43628HIGH8.5llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sample...
CVE-2026-43627HIGH8.5llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where ...
CVE-2026-41861MEDIUM4.2Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metadata attacker to make the agent write a root-owned file with ...
CVE-2026-3418CRITICAL9.1The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or desti...
CVE-2026-3415HIGH8.7The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validatio...
CVE-2026-33181Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-33942. Reason: This candidate is a ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now