2026 CVE Vulnerabilities

43,225 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48804HIGH7.5python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server store...
CVE-2026-45618CRITICAL10LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbit...
CVE-2026-19091HIGH8.1The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ...
CVE-2026-18844HIGH8.1The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (...
CVE-2026-16230CRITICAL9.8The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path vali...
CVE-2026-13457HIGH7.5The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all ...
CVE-2026-73228MEDIUM5.3Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing ...
CVE-2026-73227HIGH8.1electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al...
CVE-2026-73226HIGH8.8electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm al...
CVE-2026-73225HIGH8.1electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al...
CVE-2026-73224HIGH8.8electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al...
CVE-2026-73223HIGH8.1electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm al...
CVE-2026-73222HIGH8.8Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio ...
CVE-2026-73221MEDIUM5.3CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user...
CVE-2026-72742CRITICAL9.2DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attacke...
CVE-2026-69119HIGH8.3Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any aut...
CVE-2026-69117MEDIUM6.5NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only...
CVE-2026-69115HIGH7.1OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-o...
CVE-2026-48809HIGH7.5python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have tw...
CVE-2026-48802HIGH7.5python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an atta...
CVE-2026-18712HIGH8.1An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileg...
CVE-2026-18711HIGH7.1An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to ...
CVE-2026-18709MEDIUM6.4An issue in MongoDB Server could allow an authenticated user with direct network access to a shard to improperly commit ...
CVE-2026-18708MEDIUM6.4An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to caus...
CVE-2026-18707MEDIUM5.3An issue in MongoDB Server could allow an authenticated user, including one with no assigned privileges, to cause the se...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now