2026 CVE Vulnerabilities

64,659 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41149MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 ...
CVE-2026-41148MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 ...
CVE-2026-41104HIGH7.5Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose inform...
CVE-2026-41090CRITICAL9.3Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut...
CVE-2026-40412CRITICAL9.8Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code ...
CVE-2026-40411HIGH8.8Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.
CVE-2026-35430HIGH8.8Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized atta...
CVE-2026-33843CRITICAL9.8Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized ...
CVE-2026-26147HIGH7.7Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
CVE-2026-23663HIGH7.5Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-23652CRITICAL9.8Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an u...
CVE-2026-41147HIGH8.7NukeViet CMS is a multi Content Management System. Versions 4.5.07 and prior contain a Stored Cross-Site Scripting (XSS)...
CVE-2026-41076HIGH8.1RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 t...
CVE-2026-41075HIGH8.8RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through ...
CVE-2026-41074HIGH7.1RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Si...
CVE-2026-41073MEDIUM4.6RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0....
CVE-2026-41071HIGH8.1libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file w...
CVE-2026-41069MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file...
CVE-2026-40864MEDIUM4.3JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through ...
CVE-2026-3294HIGH8.8An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjac...
CVE-2026-5843HIGH8.6The MLX inference backend in Docker Model Runner on macOS uses the MLX-LM library, which unconditionally imports and exe...
CVE-2026-5817HIGH8.6The vllm-metal inference backend in Docker Model Runner on macOS unconditionally sets trust_remote_code=True when loadin...
CVE-2026-40610MEDIUM5.5BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1...
CVE-2026-40607HIGH7.5Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.11.0 through 2.28.1, a Stored XSS vulnerabi...
CVE-2026-40598MEDIUM6.9Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the re...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now