2026 CVE Vulnerabilities

61,333 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-47165MEDIUM4.1ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-46703CRITICAL9.6Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers ...
CVE-2026-46695CRITICAL10Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers ...
CVE-2026-46693MEDIUM4.1ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-46692MEDIUM4.1ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-46645MEDIUM4.3SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_lookup endpoint in appli...
CVE-2026-46559MEDIUM4ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-46557MEDIUM6.2ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-23...
CVE-2026-46521MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-44693HIGH8.8Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, P...
CVE-2026-42568MEDIUM4.3Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `or...
CVE-2026-42563HIGH7.7Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to v...
CVE-2026-42558HIGH7.6Xibo is an open source digital signage platform with a web content management system and Windows display player software...
CVE-2026-42305HIGH8.8Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior t...
CVE-2026-53742MEDIUM5.4Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the ...
CVE-2026-53741MEDIUM5.4Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal withou...
CVE-2026-53740MEDIUM5.4Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republi...
CVE-2026-53739MEDIUM5.1Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notic...
CVE-2026-53738HIGH8.1Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handli...
CVE-2026-53737MEDIUM6.1Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page....
CVE-2026-53736MEDIUM5.1Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handle...
CVE-2026-53634MEDIUM4.3Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before version 9.22.3, the...
CVE-2026-50131HIGH8.6Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SS...
CVE-2026-48110HIGH7.5Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.0, several russh client and serv...
CVE-2026-48108MEDIUM5.3Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now