2026 CVE Vulnerabilities

63,747 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-24444CRITICAL9.8SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability ...
CVE-2026-48735MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can cr...
CVE-2026-48526HIGH7.4PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, whil...
CVE-2026-48525MEDIUM5.3PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the u...
CVE-2026-48524LOW3.7PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP r...
CVE-2026-48523MEDIUM5.4PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list ...
CVE-2026-48522MEDIUM4.2PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to url...
CVE-2026-48156LOW3.3pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can cr...
CVE-2026-48155MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can cr...
CVE-2026-47762MEDIUM5.4TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via f...
CVE-2026-47761MEDIUM5.4TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in th...
CVE-2026-47760MEDIUM5.4TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by ...
CVE-2026-47759MEDIUM5.4TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via u...
CVE-2026-45017HIGH7.5Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and Cac...
CVE-2026-44672CRITICAL9.3mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30...
CVE-2026-44594HIGH7.5esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI...
CVE-2026-44593HIGH8.7esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first ret...
CVE-2026-44358HIGH8.2Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior t...
CVE-2026-41565HIGH7.5CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers. The gcm_dec...
CVE-2026-35676HIGH8.8phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint ...
CVE-2026-35675HIGH8.8phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthe...
CVE-2026-35672HIGH8.7phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientT...
CVE-2026-35671HIGH8.8phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint...
CVE-2026-9828LOW2.9Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-...
CVE-2026-8990MEDIUM5.3A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now