2026 CVE Vulnerabilities

65,684 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-39381MEDIUM4.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.8.0-a...
CVE-2026-39380MEDIUM5.4Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to ...
CVE-2026-39376HIGH7.5FastFeedParser is a high performance RSS, Atom and RDF parser. Prior to 0.5.10, when parse() fetches a URL that returns ...
CVE-2026-39374HIGH7.7Plane is an an open-source project management tool. Prior to 1.3.0, the IssueBulkUpdateDateEndpoint allows a project mem...
CVE-2026-39373MEDIUM5.3JWCrypto implements JWK, JWS, and JWE specifications using python-cryptography. Prior to 1.5.7, an unauthenticated attac...
CVE-2026-39371HIGH8.1RedwoodSDK is a server-first React framework. From 1.0.0-beta.50 to 1.0.5, erver functions exported from "use server" fi...
CVE-2026-39370HIGH7.1WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json.php still allows at...
CVE-2026-39369HIGH7.6WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoderReceiveImage.json.php all...
CVE-2026-39368MEDIUM6.5WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted a...
CVE-2026-39367MEDIUM5.4WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic Program Guide) featur...
CVE-2026-39366MEDIUM6.5WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler at plugin/PayPalYPT/...
CVE-2026-39365MEDIUM5.3Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s hand...
CVE-2026-39364HIGH7.5Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files...
CVE-2026-39363HIGH7.5Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to ...
CVE-2026-39361HIGH7.7OpenObserve is a cloud-native observability platform. In 0.70.3 and earlier, the validate_enrichment_url function in src...
CVE-2026-39356HIGH7.5Drizzle is a modern TypeScript ORM. Prior to 0.45.2 and 1.0.0-beta.20, Drizzle ORM improperly escaped quoted SQL identif...
CVE-2026-39322HIGH8.8PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates...
CVE-2026-32864HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds read in mgcore_SH_25_3!aligned_free() in NI LabVIEW. ...
CVE-2026-32863HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds read in sentry_transaction_context_set_operation() in...
CVE-2026-32862HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds write in ResFileFactory::InitResourceMgr() in NI LabV...
CVE-2026-32861HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVCLASS file in NI Lab...
CVE-2026-32860HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVLIB file in NI LabVI...
CVE-2026-5762MEDIUM5.3Allocation of resources without limits or throttling vulnerability in Wikimedia Foundation MediaWiki - ReportIncident Ex...
CVE-2026-5736HIGH7.3A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-serve...
CVE-2026-39360MEDIUM4.3RustFS is a distributed object storage system built in Rust. Prior to alpha.90, RustFS contains a missing authorization ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now