2026 CVE Vulnerabilities

65,684 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28390HIGH7.5Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer de...
CVE-2026-28389HIGH7.5Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer derefe...
CVE-2026-28388HIGH7.5Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference mi...
CVE-2026-28387HIGH8.1Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with u...
CVE-2026-28386HIGH7.5Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigg...
CVE-2026-39401MEDIUM5.4Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, jb child processe...
CVE-2026-39400MEDIUM6.1Cronicle is a multi-server task scheduler and runner, with a web based front-end UI. Prior to 0.9.111, a non-admin user ...
CVE-2026-39397CRITICAL9.8@delmaredigital/payload-puck is a PayloadCMS plugin for integrating Puck visual page builder. Prior to 0.6.23, all /api/...
CVE-2026-35533HIGH7.8mise manages dev tools like node, python, cmake, and terraform. From 2026.2.18 through 2026.4.5, mise loads trust-contro...
CVE-2026-34080MEDIUM5.5xdg-dbus-proxy is a filtering proxy for D-Bus connections. Prior to 0.1.7, a policy parser vulnerability allows bypassin...
CVE-2026-34045CRITICAL9.1Podman Desktop is a graphical tool for developing on containers and Kubernetes. Prior to 1.26.2, an unauthenticated HTTP...
CVE-2026-33439CRITICAL9.8Open Access Management (OpenAM) is an access management solution. Prior to 16.0.6, OpenIdentityPlatform OpenAM is vulner...
CVE-2026-32712MEDIUM5.4Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to ...
CVE-2026-29181HIGH7.5OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extractio...
CVE-2026-27949MEDIUM4.3Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentica...
CVE-2026-5741HIGH7.3A weakness has been identified in suvarchal docker-mcp-server up to 0.1.0. The impacted element is the function stop_con...
CVE-2026-5739HIGH7.3A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator....
CVE-2026-3566——Rejected reason: After further discussion, the issue was determined to not meet the criteria for CVE assignment.
CVE-2026-39841MEDIUM6.1Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Medi...
CVE-2026-39840MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundati...
CVE-2026-39839MEDIUM6.1Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Medi...
CVE-2026-39838MEDIUM6.9Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Wikimedia Foundati...
CVE-2026-39837MEDIUM5.4Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in WikiWorks Mediawiki - Car...
CVE-2026-39395MEDIUM5.3Cosign provides code signing and transparency for containers and binaries. Prior to 3.0.6 and 2.6.3, cosign verify-blob-...
CVE-2026-39382CRITICAL9.3dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now