2026 CVE Vulnerabilities

65,056 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40502HIGH8.8OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with cha...
CVE-2026-5363HIGH8.8Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery ...
CVE-2026-4880CRITICAL9.8The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPres...
CVE-2026-40947LOW2.9Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search...
CVE-2026-40245HIGH7.5Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions 4.2.1 and belo...
CVE-2026-40193HIGH8.2maddy is a composable, all-in-one mail server. Versions prior to 0.9.3 contain an LDAP injection vulnerability in the au...
CVE-2026-4949MEDIUM4.3The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres...
CVE-2026-40316HIGH8.8OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and m...
CVE-2026-40192HIGH7.5Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read...
CVE-2026-40179MEDIUM6.1Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3....
CVE-2026-39350MEDIUM5.4Istio is an open platform to connect, manage, and secure microservices. In versions 1.25.0 through 1.27.8, 1.28.0 throug...
CVE-2026-6388CRITICAL9.1A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an...
CVE-2026-40500——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. The "Add Module from URL" fe...
CVE-2026-1711MEDIUM4.8Pega Platform versions 8.1.0 through 25.1.1 are affected by a Stored Cross-Site Scripting vulnerability in a user interf...
CVE-2026-1564MEDIUM4.8Pega Platform versions 8.1.0 through 25.1.1 are affected by an HTML Injection vulnerability in a user interface componen...
CVE-2026-6398——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-40261HIGH8.8Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection ...
CVE-2026-40186MEDIUM6.1ApostropheCMS is an open-source Node.js content management system. A regression introduced in commit 49d0bb7, included i...
CVE-2026-40176HIGH7.8Composer is a dependency manager for PHP. Versions 1.0 through 2.2.26 and 2.3 through 2.9.5 contain a command injection ...
CVE-2026-40173CRITICAL9.4Dgraph is an open source distributed GraphQL database. Versions 25.3.1 and prior contain an unauthenticated credential d...
CVE-2026-22676HIGH8.5Barracuda RMM versions prior to 2025.2.2 contain a privilege escalation vulnerability that allows local attackers to gai...
CVE-2026-6385MEDIUM6.5A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/...
CVE-2026-6384HIGH7.8A flaw was found in gimp. This buffer overflow vulnerability in the GIF image loading component's `ReadJeffsImage` funct...
CVE-2026-6364MEDIUM6.5Out of bounds read in Skia in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to obtain potentially sens...
CVE-2026-6363HIGH8.8Type Confusion in V8 in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now