2026 CVE Vulnerabilities

65,293 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-6219MEDIUM5.3A vulnerability was determined in aandrew-me ytDownloader up to 3.20.2. This affects the function child_process.exec of ...
CVE-2026-6218MEDIUM5.3A vulnerability was found in aandrew-me ytDownloader up to 3.20.2. Affected by this issue is the function createTextNode...
CVE-2026-6216LOW3.5A security vulnerability has been detected in DbGate up to 7.1.4. This affects an unknown function of the file packages/...
CVE-2026-33901HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7....
CVE-2026-33900HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7....
CVE-2026-33899MEDIUM5.3ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below 7.1.2-1...
CVE-2026-33740MEDIUM5.4EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/Em...
CVE-2026-33659LOW3.1EspoCRM is an open source customer relationship management application. In versions 9.3.3 and below, the POST /api/v1/At...
CVE-2026-32272HIGH8.7Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability e...
CVE-2026-32271HIGH7.7Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there i...
CVE-2026-31280MEDIUM6.5An issue in the Bluetooth RFCOMM service of Parani M10 Motorcycle Intercom v2.1.3 allows unauthorized attackers to cause...
CVE-2026-26460MEDIUM6.1A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neu...
CVE-2026-6215MEDIUM6.3A weakness has been identified in DbGate up to 7.1.4. The impacted element is the function apiServerUrl1 of the file pac...
CVE-2026-6202MEDIUM6.3A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file po...
CVE-2026-6201MEDIUM5.4A vulnerability was identified in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the fi...
CVE-2026-33657MEDIUM5.4EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have a stored HTML inje...
CVE-2026-33534MEDIUM4.3EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below have an authenticated S...
CVE-2026-32605HIGH7.5nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a...
CVE-2026-32270LOW1.7Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the Pay...
CVE-2026-31048CRITICAL9.8An issue in the <code>pickle</code> protocol of Pyro v3.x allows attackers to execute arbitrary code via supplying a cra...
CVE-2026-6200HIGH8.8A vulnerability was determined in Tenda F456 1.0.0.5. The affected element is the function formwebtypelibrary of the fil...
CVE-2026-6199HIGH8.8A vulnerability was found in Tenda F456 1.0.0.5. Impacted is the function fromqossetting of the file /goform/qossetting....
CVE-2026-6198HIGH8.8A vulnerability has been found in Tenda F456 1.0.0.5. This issue affects the function fromNatStaticSetting of the file /...
CVE-2026-6197HIGH8.8A flaw has been found in Tenda F456 1.0.0.5. This vulnerability affects the function formWrlsafeset of the file /goform/...
CVE-2026-40044CRITICAL9.8Pachno 1.0.6 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary code by...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now