2026 CVE Vulnerabilities

62,178 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45352HIGH7.5cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size i...
CVE-2026-45324LOW3.3Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a double free in librz/core/cmd/cm...
CVE-2026-45294MEDIUM5.3FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset ...
CVE-2026-45151LOW2.9NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In 0.24.8 and earlier, quic_stream_recv can derefe...
CVE-2026-45149HIGH7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0....
CVE-2026-44640MEDIUM4.5NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_...
CVE-2026-44422HIGH8.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts on...
CVE-2026-44421HIGH8.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a h...
CVE-2026-44420HIGH8.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a h...
CVE-2026-44287MEDIUM6.3FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/...
CVE-2026-44285HIGH7.7FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allo...
CVE-2026-42500MEDIUM5.3Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid ...
CVE-2026-34127MEDIUM4.8A stored cross-site scripting (XSS) vulnerability has been identified in the web management interface of TP-Link's TL-SG...
CVE-2026-9051CRITICAL9.3There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an ...
CVE-2026-49386MEDIUM6.5In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles ...
CVE-2026-49385MEDIUM6.5In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service account...
CVE-2026-49384MEDIUM6.1In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
CVE-2026-49383LOW3.3In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
CVE-2026-49382HIGH7.8In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin
CVE-2026-49381MEDIUM4.8In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
CVE-2026-49380MEDIUM6.1In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
CVE-2026-49379MEDIUM6.5In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
CVE-2026-49378MEDIUM4.3In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion
CVE-2026-49377MEDIUM4.3In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
CVE-2026-49376MEDIUM6.5In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now