2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44659MEDIUM4.7Zen is a firefox-based browser. Prior to 1.19.12b, the ZEN Browser incorrectly truncates long hostnames in the address b...
CVE-2026-44658LOW2.4Zen is a firefox-based browser. Prior to 1.19.12b, RSS feed URLs entered by the user are validated to http: or https: in...
CVE-2026-44413HIGH7.5In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access
CVE-2026-44226MEDIUM5.3pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, pyload-ng WebUI returns fu...
CVE-2026-43995CRITICAL9.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool i...
CVE-2026-43896MEDIUM5.5jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a c...
CVE-2026-43895MEDIUM4.4jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-langu...
CVE-2026-43894MEDIUM5.5jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX...
CVE-2026-43640HIGH8.6Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an or...
CVE-2026-43639CRITICAL9.1Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user t...
CVE-2026-43638MEDIUM5.4Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to...
CVE-2026-42865MEDIUM4.3Inbox Zero is an AI personal assistant for email. Prior to 2.29.3, the cleaner email stream endpoint used a shared Redis...
CVE-2026-42860HIGH8.5The Open edx Enterprise Service app provides enterprise features to the Open edX platform. From 7.0.2 to 7.0.4, the sync...
CVE-2026-42859HIGH8.1Neat VNC is a VNC server library. Prior to 0.9.6, a pre-authentication stack buffer overflow exists in neatvnc in the RS...
CVE-2026-42858CRITICAL9.9Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in...
CVE-2026-42857MEDIUM5.4Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_ht...
CVE-2026-42856HIGH8.7Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to 5.1.3, the MCP HTTP transport accepts JSON-RPC too...
CVE-2026-42316MEDIUM6.5kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2...
CVE-2026-42315MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name...
CVE-2026-42314MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are s...
CVE-2026-42313HIGH8.3pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API...
CVE-2026-42312MEDIUM6.8pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API...
CVE-2026-41431HIGH8Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mo...
CVE-2026-41257MEDIUM5.5jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in...
CVE-2026-41256MEDIUM5.5jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncate...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now