2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8187HIGH7.5A flaw has been found in Open5GS up to 2.7.7. This impacts the function _gtpv1_u_recv_cb of the file src/upf/gtp-path.c ...
CVE-2026-8185MEDIUM6.3A security vulnerability has been detected in UGREEN CM933 1.1.59.4319. The impacted element is an unknown function of t...
CVE-2026-3828HIGH7.2Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command executi...
CVE-2026-32683MEDIUM5.3Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transm...
CVE-2026-1749MEDIUM6.8There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated u...
CVE-2026-42560CRITICAL9.1auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1...
CVE-2026-42311HIGH7.8Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could ...
CVE-2026-42310MEDIUM5.5Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF ...
CVE-2026-42309MEDIUM5.5Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to...
CVE-2026-42308MEDIUM5.5Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amo...
CVE-2026-8209MEDIUM6.9Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction...
CVE-2026-8208HIGH8.9Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the re...
CVE-2026-42461HIGH7.5Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.18.0, four GET ...
CVE-2026-42301HIGH7.8pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI ...
CVE-2026-42297HIGH8.3Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From ve...
CVE-2026-42296HIGH8.1Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t...
CVE-2026-42295MEDIUM4.9Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From ve...
CVE-2026-42294HIGH7.5Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t...
CVE-2026-42183MEDIUM6.5Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From ve...
CVE-2026-42174MEDIUM4.3Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement ...
CVE-2026-42137MEDIUM6.5Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.acc...
CVE-2026-42069MEDIUM6.5Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role...
CVE-2026-42051MEDIUM4.3Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, the system API endpoint leaks lice...
CVE-2026-41311MEDIUM6.5LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.7, a circular...
CVE-2026-41163HIGH7bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now