2026 CVE Vulnerabilities

65,045 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40476HIGH7.5graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation...
CVE-2026-40474HIGH7.6wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares per...
CVE-2026-40353MEDIUM5.4wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in Abs...
CVE-2026-40352HIGH8.8FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to N...
CVE-2026-40351CRITICAL9.8FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScri...
CVE-2026-40321HIGH8DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2026-40306MEDIUM6.5DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new in...
CVE-2026-40305MEDIUM4.3DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting i...
CVE-2026-40304MEDIUM5.3zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the unaccess handler (c...
CVE-2026-40258CRITICAL9.1The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 hav...
CVE-2026-29013CRITICAL9.8libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in ...
CVE-2026-40527HIGH8.5radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command path where crafted ...
CVE-2026-40303HIGH7.5zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, endpoints.GetSessionCoo...
CVE-2026-40302MEDIUM6.1zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template en...
CVE-2026-40301MEDIUM4.7DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style...
CVE-2026-40299MEDIUM6.9next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9....
CVE-2026-40293MEDIUM6.5OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is co...
CVE-2026-40286HIGH7.5WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul...
CVE-2026-40285HIGH8.8WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in da...
CVE-2026-40284MEDIUM6.8WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul...
CVE-2026-40282MEDIUM6.4WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul...
CVE-2026-40196HIGH8.1HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultG...
CVE-2026-40155MEDIUM5.4The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 thro...
CVE-2026-35603HIGH7.3Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide defaul...
CVE-2026-35512HIGH8.8xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynam...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now