2026 CVE Vulnerabilities

64,755 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44641HIGH7.1Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM norma...
CVE-2026-44310MEDIUM5.4Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. From 0.4.0 to before 0...
CVE-2026-44309MEDIUM5.3Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsi...
CVE-2026-42458MEDIUM5.3Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2026-42207MEDIUM6.1Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2026-42155CRITICAL9.3Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun...
CVE-2026-41258CRITICAL9.1OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptRe...
CVE-2026-41181MEDIUM5.8Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.44, 3.6.15, and 3.7.0-rc.3, there is an information di...
CVE-2026-23695MEDIUM5.4Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in t...
CVE-2026-46508HIGH7.8Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo ...
CVE-2026-45803LOW3.5`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified i...
CVE-2026-45773MEDIUM6.5Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-...
CVE-2026-45772CRITICAL9.8Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turbo...
CVE-2026-35194HIGH8.1Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated u...
CVE-2026-2031CRITICAL10An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prio...
CVE-2026-8669MEDIUM6.5Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager:...
CVE-2026-46483HIGH7Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimu...
CVE-2026-45736HIGH7.5ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is v...
CVE-2026-39054HIGH7.3Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a she...
CVE-2026-39053MEDIUM6.5Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-based XML parsing logic. When attacker-co...
CVE-2026-39052MEDIUM6.5Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String express...
CVE-2026-38728HIGH7.5An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStr...
CVE-2026-34253HIGH8.2A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in functi...
CVE-2026-46333HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The ...
CVE-2026-7182CRITICAL9.2Diagram's export module is vulnerable to Path Traversal in src attribute due to lack of HTML sanitization. An unauthenti...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now