2026 CVE Vulnerabilities

61,030 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49345MEDIUM5.3Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, ...
CVE-2026-49344HIGH7.1Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, ...
CVE-2026-49342MEDIUM5.3YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache ...
CVE-2026-48787HIGH7.4gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to t...
CVE-2026-48774HIGH7.5ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MC...
CVE-2026-48773CRITICAL9.8ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authenticat...
CVE-2026-48772CRITICAL10ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL ...
CVE-2026-48715HIGH8.8radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contai...
CVE-2026-48089HIGH7.1DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instanc...
CVE-2026-9375Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-49340HIGH8.1gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic e...
CVE-2026-49339HIGH7.1gonic is a music streaming server / free-software subsonic server API implementation. The maintainer's fix in commit `6...
CVE-2026-49338HIGH7.1gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subso...
CVE-2026-49336MEDIUM5.5@microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-prev...
CVE-2026-49293HIGH7.5js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. Versions up to and including 1.1.0 pa...
CVE-2026-49291HIGH8.1mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpo...
CVE-2026-49288MEDIUM4.3Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Con...
CVE-2026-27878MEDIUM6.5A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive...
CVE-2026-12726MEDIUM6.3A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller sto...
CVE-2026-12238MEDIUM5.3The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up t...
CVE-2026-49359MEDIUM6.5PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/...
CVE-2026-49290HIGH7.6Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Pr...
CVE-2026-49287HIGH7.4Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, the fix for CVE-2026...
CVE-2026-49286HIGH8.1PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/...
CVE-2026-49271MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder valid...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now