2026 CVE Vulnerabilities

64,369 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-47675MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the serialize() ...
CVE-2026-47674MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the ip-restricti...
CVE-2026-47673MEDIUM6.5Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, the jwt and jwk ...
CVE-2026-45292MEDIUM5.3opentelemetry-java is the Java implementation of the OpenTelemetry API for recording telemetry, and SDK for managing tel...
CVE-2026-45261CRITICAL9.3GitButler is a modern Git-based version control interface for AI-powered workflows. Prior to 0.19.7, a emote code execut...
CVE-2026-45078MEDIUM5.5Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synaps...
CVE-2026-45076LOW2.7Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers ...
CVE-2026-44543HIGH8.7Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.3...
CVE-2026-44477CRITICAL9.9CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and ...
CVE-2026-44466HIGH8.6Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expans...
CVE-2026-44465HIGH8.6Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/...
CVE-2026-44463HIGH7.8Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment ...
CVE-2026-44462HIGH8.8Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansio...
CVE-2026-44461HIGH8.6Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with ex...
CVE-2026-41185MEDIUM6.5When Calico is configured with the Azure IPAM plugin, the Calico CNI binary mutates the incoming CNI configuration to at...
CVE-2026-41184MEDIUM6.5In Calico, the install-cni init container logs the rendered CNI configuration to standard output. When the configuration...
CVE-2026-41160MEDIUM4.3EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business logic flaw (Broken Ac...
CVE-2026-41141MEDIUM6.5EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /api/v1/EmailTemplate/:...
CVE-2026-38707CRITICAL9.8A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firm...
CVE-2026-38704CRITICAL9.8A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 ...
CVE-2026-38703CRITICAL9.8A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 f...
CVE-2026-38702CRITICAL9.8A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 f...
CVE-2026-24444CRITICAL9.8SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability ...
CVE-2026-48735MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can cr...
CVE-2026-48526HIGH7.4PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, whil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now