2026 CVE Vulnerabilities

64,729 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34579MEDIUM5.3Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior are vulnerable to Authorization...
CVE-2026-5090MEDIUM6.1Template::Plugin::HTML versions before 3.103 for Perl allows HTML and JavaScript to be injected. The html_filter functi...
CVE-2026-34463HIGH8.6Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior contain a Stored XSS vulnerabil...
CVE-2026-34390MEDIUM5.1Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior have a Privilege Escalation vul...
CVE-2026-34358HIGH8.1CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contains a broken access contr...
CVE-2026-34246MEDIUM4.8CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Sc...
CVE-2026-34241HIGH8.7CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Sc...
CVE-2026-34234CRITICAL10CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (p...
CVE-2026-39250HIGH7.3An authorization vulnerability exists in Innoshop 0.6.0. After logging into the frontend, an attacker can directly acces...
CVE-2026-34233MEDIUM6.5CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, multiple admin controllers...
CVE-2026-34216MEDIUM6.6CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the admin settings update ...
CVE-2026-32882HIGH7.1libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in...
CVE-2026-32814MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid imag...
CVE-2026-32741HIGH7.1libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in ...
CVE-2026-42526MEDIUM5.3In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0...
CVE-2026-32740HIGH8.8libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (wr...
CVE-2026-32739MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequen...
CVE-2026-27173HIGH8.7JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kube...
CVE-2026-8370HIGH8.5Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power ...
CVE-2026-8096MEDIUM6.5The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypa...
CVE-2026-8073HIGH7.5The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file del...
CVE-2026-41470HIGH8.2LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows at...
CVE-2026-34154MEDIUM5.3Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1...
CVE-2026-33741MEDIUM6.8EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated use...
CVE-2026-33642CRITICAL9.8Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kit...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now