2026 CVE Vulnerabilities

64,452 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41141MEDIUM6.5EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /api/v1/EmailTemplate/:...
CVE-2026-38707CRITICAL9.8A command injection vulnerability exists in the IPSec VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 firm...
CVE-2026-38704CRITICAL9.8A command injection vulnerability exists in the WireGuard VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 ...
CVE-2026-38703CRITICAL9.8A command injection vulnerability exists in the ZeroTier VPN feature of InHand Networks IR302 firmware V3.5.108, IR305 f...
CVE-2026-38702CRITICAL9.8A command injection vulnerability exists in the Admin Access feature of InHand Networks IR302 firmware V3.5.108, IR305 f...
CVE-2026-24444CRITICAL9.8SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability ...
CVE-2026-48735MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can cr...
CVE-2026-48526HIGH7.4PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, whil...
CVE-2026-48525MEDIUM5.3PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the u...
CVE-2026-48524LOW3.7PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP r...
CVE-2026-48523MEDIUM5.4PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list ...
CVE-2026-48522MEDIUM4.2PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to url...
CVE-2026-48156LOW3.3pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can cr...
CVE-2026-48155MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can cr...
CVE-2026-47762MEDIUM5.4TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via f...
CVE-2026-47761MEDIUM5.4TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability in th...
CVE-2026-47760MEDIUM5.4TinyMCE is an open source rich text editor. From 6.8.0 to before 7.1.0, TinyMCE contains an XSS vulnerability caused by ...
CVE-2026-47759MEDIUM5.4TinyMCE is an open source rich text editor. Prior to 5.11.1, 7.9.3, and 8.5.1, there is a stored XSS vulnerability via u...
CVE-2026-45017HIGH7.5Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and Cac...
CVE-2026-44672CRITICAL9.3mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30...
CVE-2026-44594HIGH7.5esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, a Local File Inclusion (LFI...
CVE-2026-44593HIGH8.7esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first ret...
CVE-2026-44358HIGH8.2Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior t...
CVE-2026-41565HIGH7.5CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers. The gcm_dec...
CVE-2026-35676HIGH8.8phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now