2026 CVE Vulnerabilities

65,537 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-39959HIGH7.1Tmds.DBus provides .NET libraries for working with D-Bus from .NET. Tmds.DBus and Tmds.DBus.Protocol are vulnerable to m...
CVE-2026-39958CRITICAL9.1oma is a package manager for AOSC OS. Prior to 1.25.2, oma-topics is responsible for fetching metadata for testing repos...
CVE-2026-39957MEDIUM4.3Lychee is a free, open-source photo-management tool. Prior to 7.5.4, a SQL operator-precedence bug in SharingController:...
CVE-2026-39943MEDIUM6.5Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus stores revis...
CVE-2026-39942HIGH8.8Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id}...
CVE-2026-39856MEDIUM5.5osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an out-of-bounds read vulne...
CVE-2026-39855MEDIUM5.5osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.13, an integer underflow vulner...
CVE-2026-30479CRITICAL9.1A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitr...
CVE-2026-5960MEDIUM4.3A weakness has been identified in code-projects Patient Record Management System 1.0. This affects an unknown part of th...
CVE-2026-4878HIGH7A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition...
CVE-2026-39941MEDIUM6.1ChurchCRM is an open-source church management system. Prior to 7.1.0, an XSS vulnerability allows attacker-supplied inpu...
CVE-2026-39853HIGH7.8osslsigncode is a tool that implements Authenticode signing and timestamping. Prior to 2.12, A stack buffer overflow vul...
CVE-2026-39843HIGH7.7Plane is an an open-source project management tool. From 0.28.0 to before 1.3.0, the remediation of GHSA-jcc6-f9v6-f7jw ...
CVE-2026-39398——Rejected reason: The affected product and advisory are not public.
CVE-2026-35205HIGH7.8Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (...
CVE-2026-35204HIGH8.6Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, a specially crafted Helm plugin, when installe...
CVE-2026-35041MEDIUM6.5fast-jwt provides fast JSON Web Token (JWT) implementation. From 5.0.0 to 6.2.0, a denial-of-service condition exists in...
CVE-2026-35040MEDIUM5.3fast-jwt provides fast JSON Web Token (JWT) implementation. Prior to 6.2.1, using certain modifiers on RegExp objects in...
CVE-2026-34020HIGH7.5Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint us...
CVE-2026-33266HIGH7.5Use of Hard-coded Cryptographic Key vulnerability in Apache OpenMeetings. The remember-me cookie encryption key is set ...
CVE-2026-33005MEDIUM4.3Improper Handling of Insufficient Privileges vulnerability in Apache OpenMeetings. Any registered user can query web se...
CVE-2026-5959HIGH7.5A security flaw has been discovered in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1. Affected by this issue is ...
CVE-2026-5445CRITICAL9.1An out-of-bounds read vulnerability exists in the `DecodeLookupTable` function within `DicomImageDecoder.cpp`. The looku...
CVE-2026-5444HIGH7.1A heap buffer overflow vulnerability exists in the PAM image parsing logic. When Orthanc processes a crafted PAM image e...
CVE-2026-5443CRITICAL9.8A heap buffer overflow vulnerability exists during the decoding of `PALETTE COLOR` DICOM images. Pixel length validation...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now