2026 CVE Vulnerabilities

43,225 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-73244MEDIUM5.3kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /li...
CVE-2026-73243MEDIUM5.8kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /add...
CVE-2026-73242HIGH8.3FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos...
CVE-2026-73241HIGH8.3FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreer...
CVE-2026-73235MEDIUM6.1FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constru...
CVE-2026-73234HIGH7.8FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() i...
CVE-2026-73233HIGH8.5FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint t...
CVE-2026-73232HIGH7.5ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory...
CVE-2026-73231HIGH7.8Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method ...
CVE-2026-73230MEDIUM5.9Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version...
CVE-2026-73229MEDIUM4.3Django REST framework is a powerful and flexible toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's...
CVE-2026-73036MEDIUM4.6Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt...
CVE-2026-73034CRITICAL9.8DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary f...
CVE-2026-73032CRITICAL9.6PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary Jav...
CVE-2026-73031HIGH8.7telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary J...
CVE-2026-71845MEDIUM6.3A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes...
CVE-2026-71475MEDIUM5A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data ...
CVE-2026-71474MEDIUM6.3A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, whic...
CVE-2026-71468MEDIUM5.3A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly ...
CVE-2026-71467HIGH7.5A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authent...
CVE-2026-70339MEDIUM5.4Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized ...
CVE-2026-66146MEDIUM6.1Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions ...
CVE-2026-66145CRITICAL9.1An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier version...
CVE-2026-65655LOW2.3When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to ...
CVE-2026-48813HIGH8.7Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now