2026 CVE Vulnerabilities

43,246 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-18702MEDIUM6.4An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnost...
CVE-2026-18701HIGH7.1An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server ...
CVE-2026-18700MEDIUM6.5An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an i...
CVE-2026-18699MEDIUM6.5An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the ser...
CVE-2026-18698MEDIUM5.4An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag...
CVE-2026-18697HIGH8.7An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) proce...
CVE-2026-18696HIGH7An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to ...
CVE-2026-18695HIGH7.1An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could...
CVE-2026-18694HIGH7.1An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to caus...
CVE-2026-18693HIGH7.6An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges ...
CVE-2026-18692HIGH8.8An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privil...
CVE-2026-18691CRITICAL9An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influenc...
CVE-2026-18690HIGH8.1An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag...
CVE-2026-18688HIGH7.1An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory ...
CVE-2026-18687HIGH7.1MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request para...
CVE-2026-15426HIGH8.8The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v...
CVE-2026-73219MEDIUM5.3CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user...
CVE-2026-73218HIGH7.7Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in A...
CVE-2026-73217HIGH7.7Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in A...
CVE-2026-73216MEDIUM6.5Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in sr...
CVE-2026-73215HIGH7.1Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/a...
CVE-2026-73214HIGH8.2Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and cr...
CVE-2026-73213MEDIUM5.8Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_tu...
CVE-2026-73212MEDIUM5.8Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_...
CVE-2026-73211CRITICAL9.8PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now