2026 CVE Vulnerabilities

65,752 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5682LOW3.7A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android. Affected is an unknown function of t...
CVE-2026-5681MEDIUM6.3A flaw has been found in itsourcecode sanitize or validate this input 1.0. This impacts an unknown function of the file ...
CVE-2026-5679MEDIUM5.5A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_B20221024. The impacted element is the functi...
CVE-2026-35459CRITICAL9.1pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, pyLoad has a server-s...
CVE-2026-35203HIGH7.5ZLMediaKit is a streaming media service framework. the VP9 RTP payload parser in ext-codec/VP9Rtp.cpp reads multiple fie...
CVE-2026-35201MEDIUM5.9Discount is an implementation of John Gruber's Markdown markup language in C. From 1.3.1.1 to before 2.2.7.4, a signed l...
CVE-2026-35200MEDIUM5.4Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.73 ...
CVE-2026-35199MEDIUM6.1SymCrypt is the core cryptographic function library currently used by Windows. From 103.5.0 to before 103.11.0, The SymC...
CVE-2026-35197CRITICAL9.8dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would...
CVE-2026-35187HIGH7.7pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the parse_urls API fu...
CVE-2026-35185HIGH7.5HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is pub...
CVE-2026-35184CRITICAL9.8EcclesiaCRM is CRM Software for church management. Prior to 8.0.0, there is a SQL injection vulnerability in v2/template...
CVE-2026-35183MEDIUM5.4Brave CMS is an open-source CMS. Prior to 2.0.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the ...
CVE-2026-35182HIGH8.8Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update...
CVE-2026-35181MEDIUM4.3WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admi...
CVE-2026-35180MEDIUM4.3WWBN AVideo is an open source video platform. In versions 26.0 and prior, the site customization endpoint at admin/custo...
CVE-2026-35179MEDIUM5.3WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publ...
CVE-2026-35178CRITICAL9.8Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Fo...
CVE-2026-35176HIGH7.1openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exist...
CVE-2026-35172HIGH7.5Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore ...
CVE-2026-35170HIGH7.1openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exist...
CVE-2026-35022——Rejected reason: This CVE ID has been rejected by its CVE Numbering Authority (CNA). It was determined that the -p flag ...
CVE-2026-35021——Rejected reason: This CVE ID has been rejected by its CVE Numbering Authority (CNA). It was determined that the affected...
CVE-2026-35020——Rejected reason: This CVE ID has been rejected by the its CVE Numbering Authority (CNA). It was determined that the atta...
CVE-2026-5678HIGH7.3A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setSchedul...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now