2026 CVE Vulnerabilities

61,333 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48107MEDIUM6.5Russh is a Rust SSH client & server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-...
CVE-2026-48011LOW3.7Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the us...
CVE-2026-46705MEDIUM5.3Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, the russh server authe...
CVE-2026-46702HIGH7.5Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.1, when SSH compression is enabl...
CVE-2026-46689HIGH8.7Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/... endp...
CVE-2026-46679HIGH7.5libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions ...
CVE-2026-46673HIGH7.5Russh is a Rust SSH client & server library. Prior to version 0.60.3, CryptoVec used unchecked capacity growth, unchecke...
CVE-2026-46669HIGH7.5OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the...
CVE-2026-46668LOW2.3SpiceDB is an open source database system for creating and managing security-critical application permissions. From vers...
CVE-2026-46654HIGH8.9Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side...
CVE-2026-46625HIGH7.5JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal as...
CVE-2026-46523MEDIUM6.2ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.2...
CVE-2026-46522HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.2...
CVE-2026-46520HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-45783HIGH7.5libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 16.2.6, an unauthenticated remote pee...
CVE-2026-45664MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-45624MEDIUM5.1ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-45384MEDIUM6.1bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4...
CVE-2026-45380LOW3.6bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4...
CVE-2026-45359MEDIUM5.7ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-45358MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-45031MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-44692HIGH7.7Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic...
CVE-2026-42542HIGH7.5TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3...
CVE-2026-42462HIGH7Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now