2026 CVE Vulnerabilities

64,760 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44589LOW3.7Nuxt OG Image generates OG Images with Vue templates in Nuxt. The isBlockedUrl() denylist introduced in nuxt-og-image@6....
CVE-2026-44588CRITICAL9.4SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, he tooltip mouseover handler in app/src/...
CVE-2026-44586HIGH8.3SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace ...
CVE-2026-44523CRITICAL10Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JW...
CVE-2026-44522HIGH8.6Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19.4, the Note Mark application allows auth...
CVE-2026-41315CRITICAL9.8mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command ex...
CVE-2026-38740MEDIUM5.3Foscam VD1 Video Doorbell before V5.3.13_1072 is vulnerable to Cleartext Transmission of Sensitive Information. The devi...
CVE-2026-27886HIGH7.5Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did n...
CVE-2026-27680MEDIUM4.3Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inj...
CVE-2026-23998HIGH7.5Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM managem...
CVE-2026-22707MEDIUM5.4Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Con...
CVE-2026-22706MEDIUM6.5Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a...
CVE-2026-22599HIGH7.2Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5....
CVE-2026-6332HIGH7.5CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive ...
CVE-2026-46470CRITICAL9.1An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's ...
CVE-2026-46469MEDIUM5.5An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's ...
CVE-2026-44544MEDIUM4.9gittuf is a platform-agnostic Git security system. Prior to 0.14.0, an attacker with push access to gittuf's Reference S...
CVE-2026-44542CRITICAL9.1FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-contr...
CVE-2026-44520MEDIUM5.7Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit sema...
CVE-2026-44283MEDIUM4.3etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulne...
CVE-2026-42897MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows...
CVE-2026-42598MEDIUM6.9Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, t...
CVE-2026-42572MEDIUM6.5Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.83.39, a...
CVE-2026-42334HIGH7.5Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22...
CVE-2026-41888MEDIUM6.5Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELE...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now