2026 CVE Vulnerabilities

65,056 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40308HIGH8.8My Calendar is a WordPress plugin for managing calendar events. In versions 3.7.6 and below, the mc_ajax_mcjs_action AJA...
CVE-2026-40249MEDIUM5.3free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the PUT...
CVE-2026-40248HIGH7.5free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the han...
CVE-2026-40247HIGH7.5free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the han...
CVE-2026-40246HIGH7.5free5GC is an open-source implementation of the 5G core network. In versions 1.4.2 and below of the UDR service, the han...
CVE-2026-40170HIGH7.5ngtcp2 is a C implementation of the IETF QUIC protocol. In versions prior to 1.22.1, ngtcp2_qlog_parameters_set_transpor...
CVE-2026-39313HIGH8.7mcp-framework is a framework for building Model Context Protocol (MCP) servers. In versions 0.2.21 and below, the readRe...
CVE-2026-35469MEDIUM6.5spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame...
CVE-2026-34164MEDIUM4.9Valtimo is an open-source business process automation platform. In versions 13.0.0 through 13.21.0, the InboxHandlingSer...
CVE-2026-33472MEDIUM4.8Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw...
CVE-2026-40901HIGH8.8DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below ship the legacy velocit...
CVE-2026-40900HIGH8.8DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection...
CVE-2026-40899MEDIUM6.5DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a JDBC paramete...
CVE-2026-33207HIGH8.8DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection...
CVE-2026-33122CRITICAL9.8DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection...
CVE-2026-6442HIGH8.3Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands t...
CVE-2026-33121HIGH8.8DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection...
CVE-2026-33084HIGH8.8DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection...
CVE-2026-41082HIGH7.8In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
CVE-2026-33083HIGH8.8DataEase is an open-source data visualization and analytics platform. Versions 2.10.20 and below contain a SQL injection...
CVE-2026-33082CRITICAL9.8DataEase is an open source data visualization analysis tool. Versions 2.10.20 and below contain a SQL injection vulnerab...
CVE-2026-2336HIGH8.8A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared ...
CVE-2026-27820CRITICAL9.8zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 a...
CVE-2026-24749MEDIUM5.3The Silverstripe Assets Module is a required component of Silverstripe Framework. In versions prior to 2.4.5 and 3.0.0-r...
CVE-2026-41080LOW2.9libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now