2026 CVE Vulnerabilities

64,840 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40329CRITICAL9.3Masa CMS is an open source content management system. In versions 7.5.2 and earlier, a SQL injection vulnerability exist...
CVE-2026-40280HIGH7.5Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists fo...
CVE-2026-38947MEDIUM6.1FluentCMS 1.2.3 is vulnerable to Cross Site Scripting (XSS) in TextHTML plugin.
CVE-2026-35453MEDIUM5.4PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.3 and earlier, 2.0.0 through 2.1...
CVE-2026-35397HIGH8.8Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerabili...
CVE-2026-34596HIGH7Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of...
CVE-2026-34527MEDIUM5.3Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, SbieIniSe...
CVE-2026-34464HIGH8.8Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipe...
CVE-2026-34462HIGH7.8Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several P...
CVE-2026-34461HIGH7.8Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieI...
CVE-2026-34459HIGH8.8Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieS...
CVE-2026-34458HIGH8.8Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI in...
CVE-2026-34084CRITICAL9.8PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1...
CVE-2026-33975HIGH8.3Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-...
CVE-2026-33489HIGH7.5CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL s...
CVE-2026-33420MEDIUM5.3Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_det...
CVE-2026-33324HIGH8.8SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the T...
CVE-2026-33190HIGH7.5CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-D...
CVE-2026-32936HIGH7.5CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts over...
CVE-2026-32934HIGH7.5CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven i...
CVE-2026-32699MEDIUM5.3FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fai...
CVE-2026-32603MEDIUM6.5Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial...
CVE-2026-31893MEDIUM5.5Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any ...
CVE-2026-7855HIGH7.2A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /...
CVE-2026-7854CRITICAL9.8A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now