2026 CVE Vulnerabilities

64,788 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41889CRITICAL9.8pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simp...
CVE-2026-41887MEDIUM4.9Flarum is open-source forum software. Prior to versions 1.8.16 and 2.0.0-rc.1, Flarum's patch for CVE-2023-27577 restric...
CVE-2026-38360CRITICAL9.8Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execut...
CVE-2026-44499HIGH8.7ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Z...
CVE-2026-43967HIGH7.5Inefficient Algorithmic Complexity vulnerability in absinthe-graphql absinthe allows unauthenticated denial of service v...
CVE-2026-42794MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in absinthe-graphql absinthe_plug allows...
CVE-2026-42793HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in absinthe-graphql absinthe allows unauthenticated d...
CVE-2026-42353HIGH8.2i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno...
CVE-2026-41886HIGH7.5locize is a localization platform that connects code and i18n setup. Prior to version 4.0.21, the locize client SDK regi...
CVE-2026-41885MEDIUM6.5i18next-locize-backend is a simple i18next backend for locize.com which can be used in Node.js, in the browser and for D...
CVE-2026-41883HIGH8.1OmniFaces is a utility library for Faces. Prior to versions 1.14.2, 2.7.32, 3.14.16, 4.7.5, and 5.2.3, there is a server...
CVE-2026-41693HIGH8.2i18next-fs-backend is a backend layer for i18next using in Node.js and for Deno to load translations from the filesystem...
CVE-2026-41690HIGH8.618next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno....
CVE-2026-41683HIGH8.6i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno...
CVE-2026-41591MEDIUM6.4Marko is a declarative, HTML-based language for building web apps. Prior to marko version 5.38.36 and prior to @marko/ru...
CVE-2026-41070CRITICAL10openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (S...
CVE-2026-34354HIGH7.4Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escal...
CVE-2026-29975HIGH7.5lwjson 1.8.1 contains an improper input validation vulnerability in the streaming JSON parser (lwjson_stream.c). The end...
CVE-2026-29974HIGH7.5An issue was discovered in kosma minmea 0.3.0. The minmea_scan functions format specifier copies NMEA field data to a ca...
CVE-2026-29972HIGH8.2nanoMODBUS through v1.22.0 has a stack-based buffer overflow in recv_read_registers_res() in nanomodbus.c. When a client...
CVE-2026-44500MEDIUM5.3ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0, prior to zebra-chain version 7.0.0, and p...
CVE-2026-44498HIGH7.5ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, Zebra's block validator undercounts transparent ...
CVE-2026-44497CRITICAL9.1ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.4.0 and prior to zebra-script version 6.0.0, t...
CVE-2026-43475MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: scsi: storvsc: Fix scheduling while atomic on PREEM...
CVE-2026-43474MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: fs: init flags_valid before calling vfs_fileattr_ge...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now