2026 CVE Vulnerabilities

65,279 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33146MEDIUM4.3Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulnerability in versions ...
CVE-2026-33020HIGH7.1libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integ...
CVE-2026-33019HIGH7.1libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integ...
CVE-2026-33018HIGH7libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a Use-Af...
CVE-2026-27308LOW2.4ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that ...
CVE-2026-27307LOW2.4ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that ...
CVE-2026-27306HIGH8.4ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-27305HIGH8.6ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir...
CVE-2026-27304CRITICAL9.3ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-27282HIGH7.5ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-34161MEDIUM5.4Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, a Stored Cross-Site Scripting...
CVE-2026-34160HIGH8.6Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange No...
CVE-2026-33715HIGH7.2Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.aja...
CVE-2026-33714HIGH7.2Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in...
CVE-2026-27287HIGH7.8InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file...
CVE-2026-25133MEDIUM4.8October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cros...
CVE-2026-25125MEDIUM4.9October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side...
CVE-2026-24893HIGH8.8openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition ...
CVE-2026-40683HIGH7.7In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean ...
CVE-2026-34630HIGH7.8Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result ...
CVE-2026-34618HIGH7.8Illustrator versions 30.2, 29.8.5 and earlier are affected by an out-of-bounds write vulnerability that could result in ...
CVE-2026-27313HIGH7.8Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result ...
CVE-2026-27312HIGH7.8Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result ...
CVE-2026-27311HIGH7.8Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result ...
CVE-2026-27310HIGH7.8Bridge versions 16.0.2, 15.1.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now