2026 CVE Vulnerabilities

67,109 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-91134MEDIUM5.4Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the Discourse post...
CVE-2026-91133MEDIUM6.5Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, authenticated user...
CVE-2026-91132MEDIUM4.3Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, sites using wildca...
CVE-2026-91123HIGH7.2Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the iframe src tra...
CVE-2026-91122HIGH8.7Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placehol...
CVE-2026-88390HIGH7.7An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted Java...
CVE-2026-88385——Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing. Specially crafted ...
CVE-2026-88384MEDIUM5.5OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file conta...
CVE-2026-88383——libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data c...
CVE-2026-88382HIGH7.5hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate pars...
CVE-2026-88378CRITICAL9.8QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag().
CVE-2026-88377MEDIUM6.2Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. A specially ...
CVE-2026-88376HIGH7.5Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A speci...
CVE-2026-88373HIGH7.5libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL()...
CVE-2026-88372HIGH7.5libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) ...
CVE-2026-88367MEDIUM6.5NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasteriz...
CVE-2026-84302MEDIUM4.2Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI revie...
CVE-2026-79766CRITICAL9.1Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.1...
CVE-2026-79764HIGH7.7Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0...
CVE-2026-79763MEDIUM5.3Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.0...
CVE-2026-79762MEDIUM5.5Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0...
CVE-2026-63498MEDIUM5.4Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_t...
CVE-2026-63493HIGH8.1Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with ...
CVE-2026-62368HIGH8.4Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can st...
CVE-2026-56744HIGH8.7`@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@b...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now