2026 CVE Vulnerabilities

64,602 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45061HIGH7.7Budibase is an open-source low-code platform. Prior to 3.35.10, the Plugin URL upload endpoint (POST /api/plugin) valida...
CVE-2026-45047HIGH7.5bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes...
CVE-2026-44521HIGH8.8elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticate...
CVE-2026-44460HIGH7.4FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0,...
CVE-2026-44378HIGH7.5Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could ...
CVE-2026-44346HIGH8.8BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4....
CVE-2026-44345HIGH8.8BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4....
CVE-2026-42553HIGH7.1Cinny is a Matrix client. Prior to 4.10.3, A remote authenticated attacker who shares a room with a victim and has permi...
CVE-2026-42328MEDIUM6.2go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec ...
CVE-2026-38808MEDIUM5.3SQL Injection vulnerability in uzy-ssm-mall v1.1.0 allows a remote attacker to obtain sensitive information via the Prod...
CVE-2026-38807HIGH8.8Insecure Permissions vulnerability in kvf-admin v1.0.0 allows a remote attacker to escalate privileges via the UserContr...
CVE-2026-49054MEDIUM4.3Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Cont...
CVE-2026-48027CRITICAL9.8Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was publish...
CVE-2026-45335MEDIUM5.4WeGIA is a web manager for charitable institutions. Prior to 3.7.3, an Open Redirect vulnerability was identified in the...
CVE-2026-45027MEDIUM5.9WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hash...
CVE-2026-44483HIGH8.2RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6...
CVE-2026-44475MEDIUM6.1Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core does not verify the UE Security Capabil...
CVE-2026-44474LOW3.7Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concur...
CVE-2026-44473HIGH7.1Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged P...
CVE-2026-44353MEDIUM6.5Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.4.0, Streaml...
CVE-2026-44330CRITICAL10free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-pfdmanage...
CVE-2026-44329CRITICAL10free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management...
CVE-2026-44328HIGH8.2free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management...
CVE-2026-44327CRITICAL10free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-oam route...
CVE-2026-44326CRITICAL9.4free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-traffic-i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now