2026 CVE Vulnerabilities

65,045 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-26944HIGH8.8Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 r...
CVE-2026-25883MEDIUM5.8Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Ve...
CVE-2026-25058HIGH7.5Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Ve...
CVE-2026-24468MEDIUM5.3OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campa...
CVE-2026-24467CRITICAL9.8OpenAEV is an open source platform allowing organizations to plan, schedule and conduct cyber adversary simulation campa...
CVE-2026-23774HIGH7.2Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5,...
CVE-2026-6649MEDIUM6.3A vulnerability was determined in Qibo CMS 1.0. Affected by this issue is some unknown functionality of the file /index/...
CVE-2026-6369MEDIUM5.5An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local ...
CVE-2026-5760CRITICAL9.8SGLang's reranking endpoint (/v1/rerank) achieves Remote Code Execution (RCE) when a model file containing a malcious to...
CVE-2026-4048HIGH7.2OS Command Injection Remote Code Execution Vulnerability in UI in Progress ADC Products allows an authenticated attacker...
CVE-2026-3519HIGH7.2OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacke...
CVE-2026-3518HIGH7.2OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacke...
CVE-2026-3517HIGH7.2OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an authenticated attacke...
CVE-2026-33558MEDIUM5.3Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire ...
CVE-2026-33557CRITICAL9.1A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbeare...
CVE-2026-6648LOW3.5A vulnerability was found in Qibo CMS 1.0. Affected by this vulnerability is an unknown functionality of the component I...
CVE-2026-6636MEDIUM4.3A vulnerability was detected in p2r3 convert up to 6998584ace3e11db66dff0b423612a5cf91de75b. Affected is the function Bu...
CVE-2026-6635HIGH7.3A security vulnerability has been detected in rowboatlabs rowboat up to 0.1.67. This impacts the function tool_call of t...
CVE-2026-6634MEDIUM6.3A weakness has been identified in usememos memos up to 0.22.1. This affects the function memos_access_token of the file ...
CVE-2026-6633LOW3.5A security flaw has been discovered in Yifang CMS up to 2.0.5. The impacted element is the function store of the file pl...
CVE-2026-5958LOW2.1When sed is invoked with both -i (in-place edit) and --follow-symlinks, the function open_next_file() performs two separ...
CVE-2026-6654MEDIUM5.1Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic...
CVE-2026-6632HIGH8.8A vulnerability was identified in Tenda F451 1.0.0.7_cn_svn7958. The affected element is the function fromSafeClientFilt...
CVE-2026-6631HIGH8.8A vulnerability was determined in Tenda F451 1.0.0.7_cn_svn7958. Impacted is the function fromwebExcptypemanFilter of th...
CVE-2026-6630HIGH8.8A vulnerability was found in Tenda F451 1.0.0.7_cn_svn7958. This issue affects the function fromGstDhcpSetSer of the fil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now