2026 CVE Vulnerabilities

44,998 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-45313HIGH7.7Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegist...
CVE-2026-36590HIGH7.5An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in...
CVE-2026-62312HIGH8.89Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitra...
CVE-2026-59950HIGH8.1The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1,...
CVE-2026-56679HIGH8.79Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body t...
CVE-2026-49353HIGH7.59Router is an AI router & token saver. In 0.4.45 and earlier, 9Router's src/dashboardGuard.js local-only access gate use...
CVE-2026-56742HIGH8.9Cilium is a networking, observability, and security solution. Prior to 1.17.17, 1.18.11, and 1.19.5, Cilium clusters usi...
CVE-2026-52870HIGH7.6The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). From 1.23.0 unti...
CVE-2026-52869HIGH7.1The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.27.2,...
CVE-2026-50144HIGH7.1ncnn is a high-performance neural network inference framework optimized for the mobile platform. In commit e54f7b1f88434...
CVE-2026-50124HIGH7.1DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploadin...
CVE-2026-50030HIGH7.1DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL preview exposes DatasetD...
CVE-2026-49445HIGH8.8Cilium is a networking, observability, and security solution. Prior to 1.17.14, 1.18.8, and 1.19.2, when Cilium L7 funct...
CVE-2026-45738HIGH8.7Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Prior to 3.2.12, 3.3.10, and 3.4.2, Argo CD us...
CVE-2026-45535HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase SQL-type datasets store atta...
CVE-2026-45533HIGH8.3DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase export-center deletion can a...
CVE-2026-45419HIGH8.5DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call Template...
CVE-2026-45417HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase datasource connection status...
CVE-2026-45320HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase dashboard SQL variables such...
CVE-2026-40957HIGH7.5o   CVE-2026-40957 is a frameable content vulnerability in the Secure Access server login page prior to 14.55. Attackers...
CVE-2026-40952HIGH7.8CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to...
CVE-2026-62351HIGH7.5TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/sr...
CVE-2026-62350HIGH7.2TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user wit...
CVE-2026-62349HIGH8.3TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, sourc...
CVE-2026-49987HIGH7.5Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitSha...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now