2026 CVE Vulnerabilities

65,619 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-39881HIGH7.8Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans ...
CVE-2026-39860HIGH8.4Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary ove...
CVE-2026-39844HIGH7.5NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path...
CVE-2026-39429CRITICAL9.1kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior t...
CVE-2026-39416MEDIUM6.1AIL framework is an open-source platform to collect, crawl, process and analyse unstructured data. Prior to 6.8, a store...
CVE-2026-39415MEDIUM4.3Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.46.0, ...
CVE-2026-39414MEDIUM6.5MinIO is a high-performance object storage system. From RELEASE.2018-08-18T03-49-57Z to before RELEASE.2025-12-20T04-58-...
CVE-2026-5802HIGH7.3A vulnerability was identified in idachev mcp-javadc up to 1.2.4. Impacted is an unknown function of the component HTTP ...
CVE-2026-39880MEDIUM4.9Remnawave Backend is the backend for the Remnawave proxy and user management solution. Prior to 2.7.5, a glitch in the H...
CVE-2026-39864MEDIUM4.9Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.0.5 and 5.8.7, an out-of-bounds read in ...
CVE-2026-39863HIGH7.5Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds ...
CVE-2026-39862HIGH8.8Tophat is a mobile applications testing harness. Prior to 2.5.1, Tophat is affected by remote code execution via crafted...
CVE-2026-39859HIGH7.5LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, liquidjs 10.25.0 d...
CVE-2026-39413MEDIUM6.5LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.4.14, the LightRAG API is vulnerable to a J...
CVE-2026-39412HIGH7.5LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.4, the sort_natural f...
CVE-2026-39411HIGH7.1LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to ...
CVE-2026-39362HIGH7.1InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is e...
CVE-2026-35525HIGH7.5LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, for {% include %},...
CVE-2026-35479MEDIUM4.7InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, any users who have staff access permi...
CVE-2026-35478HIGH8.1InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user c...
CVE-2026-35477CRITICAL9.9InvenTree is an Open Source Inventory Management System. From 1.2.3 to 1.2.6, the fix for CVE-2026-27629 upgraded the PA...
CVE-2026-35476MEDIUM4.3InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, a non-staff authenticated user can el...
CVE-2026-23869HIGH7.5A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-...
CVE-2026-39851MEDIUM4.3Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange...
CVE-2026-35455MEDIUM5.4immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripti...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now