2026 CVE Vulnerabilities

65,537 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5971CRITICAL9.8A flaw has been found in FoundationAgents MetaGPT up to 0.8.1. This vulnerability affects the function ActionNode.xml_fi...
CVE-2026-5970CRITICAL9.8A vulnerability was detected in FoundationAgents MetaGPT up to 0.8.1. This affects the function check_solution of the co...
CVE-2026-5329MEDIUM6.5Rapid7 Velociraptor versions prior to 0.76.2 contain an improper input validation vulnerability in the client monitoring...
CVE-2026-40072HIGH7.2web3.py allows you to interact with the Ethereum blockchain using Python. From 6.0.0b3 to before 7.15.0 and 8.0.0b2, web...
CVE-2026-40071MEDIUM5.4pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the /json/package_order, /j...
CVE-2026-40070HIGH8.1BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.3.1 to before 0.8.2, BSV::Wallet::WalletClient#acquire_certi...
CVE-2026-40069HIGH7.5BSV Ruby SDK is the Ruby SDK for the BSV blockchain. From 0.1.0 to before 0.8.2, BSV::Network::ARC's failure detection o...
CVE-2026-39987CRITICAL9.8marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket e...
CVE-2026-39985MEDIUM6.1LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project...
CVE-2026-39983HIGH8.6basic-ftp is an FTP client for Node.js. Prior to 5.2.1, basic-ftp allows FTP command injection via CRLF sequences (\r\n)...
CVE-2026-39981HIGH8.8AGiXT is a dynamic AI Agent Automation Platform. Prior to 1.9.2, the safe_join() function in the essential_abilities ext...
CVE-2026-39980HIGH7.2OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the...
CVE-2026-39961MEDIUM4.9Aiven Operator allows you to provision and manage Aiven Services from your Kubernetes cluster. From 0.31.0 to before 0.3...
CVE-2026-39911HIGH8.8Hashgraph Guardian through version 3.5.1, fixed in commit 45fbe2f, contains an unsandboxed JavaScript execution vulnerab...
CVE-2026-39315MEDIUM6.1Unhead is a document head and template manager. Prior to 2.1.13, useHeadSafe() is the composable that Nuxt's own documen...
CVE-2026-35207MEDIUM5.4dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-contr...
CVE-2026-30478HIGH8.8A Dynamic-link Library Injection vulnerability in GatewayGeo MapServer for Windows version 5 allows attackers to escalat...
CVE-2026-1584HIGH7.5A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially cra...
CVE-2026-5962CRITICAL9.8A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function R7WebsSecurityHandlerfunction o...
CVE-2026-5961HIGH7.3A security vulnerability has been detected in code-projects Simple IT Discussion Forum 1.0. This vulnerability affects u...
CVE-2026-40046HIGH7.5Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for...
CVE-2026-39976HIGH7.1Laravel Passport provides OAuth2 server support to Laravel. From 13.0.0 to before 13.7.1, there is an Authentication Byp...
CVE-2026-39974HIGH8.5n8n-MCP is a Model Context Protocol (MCP) server that provides AI assistants with comprehensive access to n8n node docum...
CVE-2026-39972HIGH7.1Mercure is a protocol for pushing data updates to web browsers and other HTTP clients in a battery-efficient way. Prior ...
CVE-2026-39962CRITICAL9.6MISP is an open source threat intelligence and sharing platform. Prior to 2.5.36, improper neutralization of special ele...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now