2026 CVE Vulnerabilities

64,471 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44724HIGH7.8systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation...
CVE-2026-44681MEDIUM6.1Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated...
CVE-2026-44590CRITICAL9.3Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workfl...
CVE-2026-42877MEDIUM5.4FacturaScripts is an open source accounting and invoicing software. In 2025.92 and earlier, a stored Cross-Site Scriptin...
CVE-2026-42197HIGH8.7RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a store...
CVE-2026-33552LOW3.7Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.
CVE-2026-8716MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, an...
CVE-2026-6713MEDIUM5.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, an...
CVE-2026-5296MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.10.7, 18.11 before 18.11.4, and 1...
CVE-2026-4868HIGH8.2GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 1...
CVE-2026-45046MEDIUM5.5Gryph provides a security layer for AI coding agents. Prior to 0.7.0, Gryph implements logging levels that determine wha...
CVE-2026-44635HIGH7.5Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does n...
CVE-2026-42879MEDIUM6.3FacturaScripts is an open source accounting and invoicing software. In 2025.81 and earlier, an authenticated unrestricte...
CVE-2026-42878MEDIUM5.3FacturaScripts is an open source accounting and invoicing software. Prior to v2026, an unauthenticated information discl...
CVE-2026-2601MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 1...
CVE-2026-1402MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, an...
CVE-2026-5509HIGH7.2An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an admin...
CVE-2026-4392MEDIUM6.9A vulnerability was detected in TeamSpeak 3 Server up to 3.13.7. This issue affects some unknown processing of the compo...
CVE-2026-4391MEDIUM6.9A security vulnerability has been detected in TeamSpeak 3 Server up to 3.13.7. This vulnerability affects unknown code o...
CVE-2026-4390MEDIUM5.4A weakness has been identified in TeamSpeak 3 Server up to 3.13.7. This affects the function process_resend_queue of the...
CVE-2026-48153HIGH8.5Budibase is an open-source low-code platform. Prior to 3.39.0, fetchToken in the OAuth2 SDK makes a POST to a builder-su...
CVE-2026-48152HIGH8.1Budibase is an open-source low-code platform. Prior to 3.39.0, the single-datasource GET and PUT routes are guarded by g...
CVE-2026-48151HIGH7.5Budibase is an open-source low-code platform. Prior to 3.39.0, the webhook schema-building endpoint is registered under ...
CVE-2026-48150CRITICAL9Budibase is an open-source low-code platform. Prior to 3.39.0, /api/public/v1/roles/assign is guarded by the builderOrAd...
CVE-2026-48149HIGH8.1Budibase is an open-source low-code platform. Prior to 3.39.0, the Budibase Text component renders markdown by assigning...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now