2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44427NONE0The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. From 1.1.0 to 1.7.4...
CVE-2026-45781LOW3.5The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.9, OCI...
CVE-2026-45370HIGH7.7python-utcp is the python implementation of UTCP. Prior to 1.1.3, _prepare_environment() in cli_communication_protocol.p...
CVE-2026-45369HIGH8.3python-utcp is the python implementation of UTCP. Prior to 1.1.3, the _substitute_utcp_args method in cli_communication_...
CVE-2026-44700HIGH8.7Elixir WebRTC is an Elixir implementation of the W3C WebRTC API. Prior to 0.15.1 and 0.16.1, missing DTLS peer certifica...
CVE-2026-44679MEDIUM6.9Tuist is a virtual platform team for Swift app devs. Prior to 1.180.10, the forgot password flow allows an unauthenticat...
CVE-2026-44678HIGH7.1Tuist is a virtual platform team for Swift app devs. In 1.180.8 and earlier, the DELETE /api/projects/{account_handle}/{...
CVE-2026-44673HIGH7.5libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an ...
CVE-2026-44666CRITICAL9.3HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool. Prior to 3.3.8, the sanitizeStri...
CVE-2026-44662MEDIUM5.1rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.0 to before 0.10.79, CipherCtxRef::c...
CVE-2026-44661MEDIUM4.7python-utcp is the python implementation of UTCP. Prior to 1.1.3, the utcp-http plugin is vulnerable to a blind Server-S...
CVE-2026-44647HIGH7.1OneDev is a Git server with CI/CD, kanban, and packages. Prior to 15.0.2, there is behavior that breaks the expected bou...
CVE-2026-44430MEDIUM4The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the...
CVE-2026-44429MEDIUM5.4The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the...
CVE-2026-44212CRITICAL9.3PrestaShop is an open source e-commerce web application. Prior to 8.2.6 and 9.1.1, there is a stored Cross-Site Scriptin...
CVE-2026-42847HIGH7.1ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #122, there is a critical SQL Injection (SQLi) ...
CVE-2026-42327HIGH8.7rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_re...
CVE-2026-8634CRITICAL9.3Crabbox prior to v0.12.0 contains an environment variable exposure vulnerability that allows attackers with access to a ...
CVE-2026-8629HIGH8.6Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only acc...
CVE-2026-8597HIGH7.2Missing integrity verification in the Triton inference handler in Amazon SageMaker Python SDK v2 before v2.257.2 and v3 ...
CVE-2026-8596HIGH8.5Cleartext storage of sensitive information in the ModelBuilder/Serve component in Amazon SageMaker Python SDK before v2....
CVE-2026-8587HIGH8.8Use after free in Extensions in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to...
CVE-2026-8586MEDIUM5.5Inappropriate implementation in Chromoting in Google Chrome prior to 148.0.7778.168 allowed a local attacker to bypass d...
CVE-2026-8585HIGH7.5Inappropriate implementation in Media in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had ...
CVE-2026-8584MEDIUM4.2Inappropriate implementation in Views in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now