2026 CVE Vulnerabilities

65,045 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40480HIGH7.1ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoin...
CVE-2026-40349HIGH8.8Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti...
CVE-2026-40348HIGH7.7Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti...
CVE-2026-40347MEDIUM5.3Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerabi...
CVE-2026-40346MEDIUM6.5NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-40341LOW3.5libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_u...
CVE-2026-40340MEDIUM6.1libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read vulner...
CVE-2026-40339MEDIUM5.2libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `pt...
CVE-2026-40338MEDIUM5.2libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the...
CVE-2026-40337MEDIUM5.1The Sentry kernel is a high security level micro-kernel implementation made for high security embedded systems. A given ...
CVE-2026-40336LOW2.4libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have a memory leak in `ptp_unpack...
CVE-2026-40335MEDIUM5.2libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in `pt...
CVE-2026-40334LOW3.5libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, a missing null terminator exi...
CVE-2026-40333MEDIUM6.1libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, two functions in camlibs/ptp2...
CVE-2026-40324CRITICAL9.1Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's...
CVE-2026-40323HIGH7.5SP1 is a zero‑knowledge virtual machine that proves the correct execution of programs compiled for the RISC-V architectu...
CVE-2026-2262HIGH7.5The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in...
CVE-2026-5250——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-40486MEDIUM4.3Kimai is an open-source time tracking application. In versions 2.52.0 and below, the User Preferences API endpoint (PATC...
CVE-2026-40481HIGH7.5monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoi...
CVE-2026-40479MEDIUM5.4Kimai is an open-source time tracking application. In versions 1.16.3 through 2.52.0, the escapeForHtml() function in Ki...
CVE-2026-2434MEDIUM6.4The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attribute...
CVE-2026-5720CRITICAL9.1miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause...
CVE-2026-40478CRITICAL9Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior co...
CVE-2026-40477CRITICAL9Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior co...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now