2026 CVE Vulnerabilities

65,664 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34371MEDIUM6.3LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e...
CVE-2026-34079HIGH7.5Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes out...
CVE-2026-34078CRITICAL10Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths ...
CVE-2026-31790HIGH7.5Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an ...
CVE-2026-31789CRITICAL9.8Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflo...
CVE-2026-28390HIGH7.5Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer de...
CVE-2026-28389HIGH7.5Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer derefe...
CVE-2026-28388HIGH7.5Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference mi...
CVE-2026-28387HIGH8.1Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with u...
CVE-2026-28386HIGH7.5Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigg...
CVE-2026-39401MEDIUM5.4Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processe...
CVE-2026-39400MEDIUM6.1Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, a non-admin user ...
CVE-2026-39397CRITICAL9.8@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/...
CVE-2026-35533HIGH7.8mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-contro...
CVE-2026-34080MEDIUM5.5xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassin...
CVE-2026-34045CRITICAL9.1Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP...
CVE-2026-33439CRITICAL9.8Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulner...
CVE-2026-32712MEDIUM5.4Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to ...
CVE-2026-29181HIGH7.5OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extractio...
CVE-2026-27949MEDIUM4.3Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentica...
CVE-2026-5741HIGH7.3A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_con...
CVE-2026-5739HIGH7.3A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator....
CVE-2026-3566——Rejected reason: After further discussion, the issue was determined to not meet the criteria for CVE assignment.
CVE-2026-39841MEDIUM6.1Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Medi...
CVE-2026-39840MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundati...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now