2026 CVE Vulnerabilities

65,063 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-39399CRITICAL9.6NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend...
CVE-2026-39387HIGH7.2BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. V...
CVE-2026-35589CRITICAL9.3nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerabili...
CVE-2026-35034MEDIUM6.5Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability...
CVE-2026-35033CRITICAL9.1Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file...
CVE-2026-35032HIGH8.1Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the Live...
CVE-2026-35031HIGH8.8Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subt...
CVE-2026-34457CRITICAL9.1OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a ...
CVE-2026-34454LOW3.5OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 p...
CVE-2026-33414HIGH7.8Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerab...
CVE-2026-33023HIGH7.8libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. In versions 1.8.7 and prior, when built w...
CVE-2026-33021HIGH7.3libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a use-af...
CVE-2026-27301MEDIUM5.5Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead ...
CVE-2026-27300MEDIUM5.5Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could...
CVE-2026-27299MEDIUM6.3Adobe Framemaker versions 2022.8 and earlier are affected by an Improper Input Validation vulnerability that could lead ...
CVE-2026-27298HIGH7.8Adobe Framemaker versions 2022.8 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confus...
CVE-2026-27297HIGH7.8Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability tha...
CVE-2026-27296HIGH7.8Adobe Framemaker versions 2022.8 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability tha...
CVE-2026-27295HIGH7.8Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds write vulnerability that could result in a...
CVE-2026-27294HIGH7.8Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted ...
CVE-2026-27293HIGH7.8Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could resul...
CVE-2026-27292HIGH7.8Adobe Framemaker versions 2022.8 and earlier are affected by a Use After Free vulnerability that could result in arbitra...
CVE-2026-27290HIGH8.6Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow att...
CVE-2026-40291HIGH8.8Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object mod...
CVE-2026-39907CRITICAL10Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now