2026 CVE Vulnerabilities

64,848 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33190HIGH7.5CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-D...
CVE-2026-32936HIGH7.5CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts over...
CVE-2026-32934HIGH7.5CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven i...
CVE-2026-32699MEDIUM5.3FacturaScripts is an open source accounting and invoicing software. In versions 2025.92 and earlier, the application fai...
CVE-2026-32603MEDIUM6.5Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial...
CVE-2026-31893MEDIUM5.5Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any ...
CVE-2026-7855HIGH7.2A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /...
CVE-2026-7854CRITICAL9.8A security vulnerability has been detected in D-Link DI-8100 16.07.26A1. Affected by this vulnerability is the function ...
CVE-2026-42997HIGH7.7An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request aut...
CVE-2026-38428CRITICAL9.8Kestra v1.3.3 and before is vulnerable to SQL Injection. The vulnerability occurs because user-controlled input from a G...
CVE-2026-31835MEDIUM5.4Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authenticatio...
CVE-2026-30923HIGH7.5ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsec...
CVE-2026-27960CRITICAL9.8OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 t...
CVE-2026-7853CRITICAL9.8A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.a...
CVE-2026-7851HIGH7.3A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The...
CVE-2026-7847LOW2.6A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The affected element is the function _get_...
CVE-2026-43002MEDIUM5.3An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session stor...
CVE-2026-38432MEDIUM6.1ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with ...
CVE-2026-38431CRITICAL9.8ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to crea...
CVE-2026-38429CRITICAL9.8OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML par...
CVE-2026-25589HIGH8.8RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module ...
CVE-2026-25588HIGH8.8RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does no...
CVE-2026-25243HIGH8.8Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not proper...
CVE-2026-23631HIGH8.1Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacke...
CVE-2026-23479HIGH8.8Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not han...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now