2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45362LOW3.2Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.
CVE-2026-45321CRITICAL9.6On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were publ...
CVE-2026-8349MEDIUM4.3A flaw has been found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGAP Mes...
CVE-2026-8346HIGH8.8A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing...
CVE-2026-8345HIGH8.8A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the funct...
CVE-2026-43914CRITICAL9.8Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaul...
CVE-2026-43913HIGH8.1Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organiz...
CVE-2026-43912HIGH8.7Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a group...
CVE-2026-43911HIGH8.1Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when t...
CVE-2026-43901MEDIUM6.8Wireshark MCP is an MCP Server that turns tshark into a structured analysis interface, then layers in optional Wireshark...
CVE-2026-43900CRITICAL9.3DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0....
CVE-2026-43899CRITICAL9.6DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0....
CVE-2026-42554MEDIUM6.1Fiber is a web framework for Go. Prior to 2.52.12 and 3.1.0, Cross-Site Scripting vulnerability in Go Fiber allows a rem...
CVE-2026-34963HIGH7.8barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe...
CVE-2026-34962MEDIUM5.5barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_...
CVE-2026-8344HIGH8.8A weakness has been identified in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this vulnerability is the function ...
CVE-2026-7010MEDIUM6.5HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values. Th...
CVE-2026-44695MEDIUM6.5Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET...
CVE-2026-43897HIGH8.7Link Preview JS extracts web links information. Prior to 4.0.1, the library did not check for IPv6 loopback attacks. The...
CVE-2026-43893HIGH8.2exiftool-vendored provides cross-platform Node.js access to ExifTool. Prior to 35.19.0, exiftool-vendored starts ExifToo...
CVE-2026-43890HIGH7.7Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.7.0, the subscriptions.create API end...
CVE-2026-43889MEDIUM6.5Outline is a service that allows for collaborative documentation. Prior to 1.7.0, the shares.create API accepts both col...
CVE-2026-43888HIGH8.7Outline is a service that allows for collaborative documentation. Prior to 1.7.0, ZipHelper.extract computes the extract...
CVE-2026-43887HIGH7.3Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, the Outline comment section perm...
CVE-2026-43886HIGH8.2Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, a logic error in OAuthInterface....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now