2026 CVE Vulnerabilities

63,732 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44462HIGH8.8Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansio...
CVE-2026-44461HIGH8.6Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with ex...
CVE-2026-41185MEDIUM6.5When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to at...
CVE-2026-41184MEDIUM6.5In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration...
CVE-2026-41160MEDIUM4.3EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business logic flaw (Broken Ac...
CVE-2026-41141MEDIUM6.5EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /api/v1/EmailTemplate/:...
CVE-2026-38707CRITICAL9.8A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firm...
CVE-2026-38704CRITICAL9.8A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 ...
CVE-2026-38703CRITICAL9.8A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 f...
CVE-2026-38702CRITICAL9.8A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 f...
CVE-2026-24444CRITICAL9.8SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability ...
CVE-2026-48735MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can cr...
CVE-2026-48526HIGH7.4PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, whil...
CVE-2026-48525MEDIUM5.3PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the u...
CVE-2026-48524LOW3.7PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP r...
CVE-2026-48523MEDIUM5.4PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list ...
CVE-2026-48522MEDIUM4.2PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to url...
CVE-2026-48156LOW3.3pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can cr...
CVE-2026-48155MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can cr...
CVE-2026-47762MEDIUM5.4TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via f...
CVE-2026-47761MEDIUM5.4TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in th...
CVE-2026-47760MEDIUM5.4TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by ...
CVE-2026-47759MEDIUM5.4TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via u...
CVE-2026-45017HIGH7.5Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and Cac...
CVE-2026-44672CRITICAL9.3mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now