2026 CVE Vulnerabilities

65,754 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-35043HIGH7.8BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4....
CVE-2026-30613MEDIUM4.6An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Ver...
CVE-2026-5670MEDIUM6.3A vulnerability was found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This is...
CVE-2026-5669HIGH7.3A vulnerability has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Th...
CVE-2026-5668LOW2.4A flaw has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. This affect...
CVE-2026-35042HIGH7.5fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (C...
CVE-2026-35039CRITICAL9.1fast-jwt provides fast JSON Web Token (JWT) implementation. From 0.0.1 to before 6.2.0, setting up a custom cacheKeyBuil...
CVE-2026-35037HIGH7.2Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, the GET /api/website/...
CVE-2026-35036HIGH7.5Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, Ech0 implements link ...
CVE-2026-35035CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-35030CRITICAL9.4LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authenti...
CVE-2026-35029HIGH8.8LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/updat...
CVE-2026-34992HIGH7.5Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to 2.4.5 and 2.5.2, a missing encrypt...
CVE-2026-34989CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-34986HIGH7.5Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including sup...
CVE-2026-34981MEDIUM5.8The whisperX API is a tool for enhancing and analyzing audio content. From 0.3.1 to 0.5.0, FileService.download_from_url...
CVE-2026-34977CRITICAL9.8Aperi'Solve is an open-source steganalysis web platform. In versions 3.1.3 through 3.2.0, when uploading a JPEG, a user ...
CVE-2026-34976CRITICAL10Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from...
CVE-2026-34975MEDIUM4.3Plunk is an open-source email platform built on top of AWS SES. Prior to 0.8.0, a CRLF header injection vulnerability wa...
CVE-2026-34841CRITICAL9.8Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack ...
CVE-2026-34783HIGH8.1Ferret is a declarative system for working with web data. Prior to 2.0.0-alpha.4, a path traversal vulnerability in Ferr...
CVE-2026-31313MEDIUM5.4An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allo...
CVE-2026-5704MEDIUM5.5A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to ...
CVE-2026-5666MEDIUM5.5A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionalit...
CVE-2026-5665HIGH7.3A security vulnerability has been detected in code-projects Online FIR System 1.0. Affected by this vulnerability is an ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now