2026 CVE Vulnerabilities

64,755 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-46360MEDIUM5.4phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that lim...
CVE-2026-46359HIGH7.7phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated atta...
CVE-2026-45800HIGH8.7Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3...
CVE-2026-45622MEDIUM5.3Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3...
CVE-2026-45616MEDIUM5.1Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3...
CVE-2026-45010CRITICAL9.3phpMyFAQ before 4.1.2 contains an improper restriction of excessive authentication attempts vulnerability in the /admin/...
CVE-2026-45009MEDIUM5.3phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated...
CVE-2026-45008HIGH7phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INST...
CVE-2026-45007MEDIUM5.3phpMyFAQ before 4.1.2 contains missing permission checks in ConfigurationTabController.php where 12 endpoints use userIs...
CVE-2026-44826HIGH7.5Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.2...
CVE-2026-44719MEDIUM5.3Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to befor...
CVE-2026-44718MEDIUM5.3Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to befor...
CVE-2026-44366MEDIUM6.1Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.1...
CVE-2026-46474HIGH7.5Trog::TOTP versions before 1.006 for Perl generate secrets using rand. Secrets were generated using Perl's built-in ran...
CVE-2026-8695CRITICAL9.8radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_threads_list() function that allows remote attackers t...
CVE-2026-46383MEDIUM5.5Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM conta...
CVE-2026-45539HIGH7.4Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive ...
CVE-2026-45038HIGH7.8Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape cont...
CVE-2026-45037HIGH7.1Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passe...
CVE-2026-45036HIGH7Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby before 1.0.233 automatical...
CVE-2026-45035HIGH8.8Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the ha...
CVE-2026-44774CRITICAL9.9Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway AP...
CVE-2026-44717CRITICAL9.8MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the ...
CVE-2026-44714HIGH7.5The bitcoinj library is a Java implementation of the Bitcoin protocol. Prior to 0.17.1, ScriptExecution.correctlySpends(...
CVE-2026-44699CRITICAL9.1LibJWT is a C JSON Web Token Library. From 3.0.0 to 3.3.2, libjwt accepts an RSA JWK that does not contain an alg parame...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now