2026 CVE Vulnerabilities

65,279 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40096MEDIUM5.4immich is a high performance self-hosted photo and video management solution. Versions prior to 2.7.3 contain an open re...
CVE-2026-40091MEDIUM4.4SpiceDB is an open source database system for creating and managing security-critical application permissions. In versio...
CVE-2026-40090HIGH7.1Zarf is an Airgap Native Packager Manager for Kubernetes. Versions 0.23.0 through 0.74.1 contain an arbitrary file write...
CVE-2026-39984MEDIUM5.5Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Versions 2.0.5 and below contain an authoriza...
CVE-2026-39971HIGH7.2Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the email sending functionality in include/...
CVE-2026-39963MEDIUM6.9Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the serendipity_setCookie() function in in...
CVE-2026-39884HIGH8.1mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Versions 3.4.0 and prior con...
CVE-2026-39842CRITICAL9.9OpenRemote is an open-source IoT platform. Versions 1.21.0 and below contain two interrelated expression injection vulne...
CVE-2026-33806HIGH7.5Impact: Fastify applications using schema.body.content for per-content-type body validation can have validation bypasse...
CVE-2026-2834HIGH7.2The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to Stored Cross-Site S...
CVE-2026-2396MEDIUM4.4The List View Google Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event descriptio...
CVE-2026-1555CRITICAL9.8The WebStack theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the io_i...
CVE-2026-1541MEDIUM4.3The Avada (Fusion) Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, a...
CVE-2026-1509MEDIUM5.4The Avada (Fusion) Builder plugin for WordPress is vulnerable to Arbitrary WordPress Action Execution in all versions up...
CVE-2026-1314MEDIUM5.3The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to unauth...
CVE-2026-40688HIGH7.2An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 th...
CVE-2026-39399CRITICAL9.6NuGet Gallery is a package repository that powers nuget.org. A security vulnerability exists in the NuGetGallery backend...
CVE-2026-39387HIGH7.2BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. V...
CVE-2026-35589CRITICAL9.3nanobot is a personal AI assistant. Versions prior to 0.1.5 contain a Cross-Site WebSocket Hijacking (CSWSH) vulnerabili...
CVE-2026-35034MEDIUM6.5Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability...
CVE-2026-35033CRITICAL9.1Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file...
CVE-2026-35032HIGH8.1Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the Live...
CVE-2026-35031HIGH8.8Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subt...
CVE-2026-34457CRITICAL9.1OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions prior to 7.15.2 contain a ...
CVE-2026-34454LOW3.5OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 p...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now