2026 CVE Vulnerabilities

65,801 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34950CRITICAL9.1fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-...
CVE-2026-34940HIGH8.8KubeAI is an AI inference operator for kubernetes. Prior to 0.23.2, the ollamaStartupProbeScript() function in internal/...
CVE-2026-34764MEDIUM5.5Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alph...
CVE-2026-34756MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Servi...
CVE-2026-34755MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO....
CVE-2026-34753MEDIUM5.4vLLM is an inference and serving engine for large language models (LLMs). From 0.16.0 to before 0.19.0, a server-side re...
CVE-2026-34589MEDIUM5OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-34588HIGH7.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-34444CRITICAL10Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently ap...
CVE-2026-34402——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-39330. Reason: This candidate is a ...
CVE-2026-34380MEDIUM5.9OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-34379HIGH7.1OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-34378MEDIUM6.5OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-34217HIGH7.2SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, a scope modification vulnerability exists in @nyariv/sand...
CVE-2026-34211HIGH7.5SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, the @nyariv/sandboxjs parser contains unbounded recursion...
CVE-2026-34208CRITICAL10SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for...
CVE-2026-34148HIGH7.5Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8,...
CVE-2026-33752HIGH8.6curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges,...
CVE-2026-33727MEDIUM6.7Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privil...
CVE-2026-33405MEDIUM4.8Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic...
CVE-2026-31354MEDIUM5.4Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 a...
CVE-2026-31353MEDIUM5.4An authenticated stored cross-site scripting (XSS) vulnerability in the Category module of Feehi CMS v2.1.1 allows attac...
CVE-2026-31352MEDIUM5.4An authenticated stored cross-site scripting (XSS) vulnerability in the Role Management module of Feehi CMS v2.1.1 allow...
CVE-2026-31351MEDIUM4.8An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allo...
CVE-2026-31350MEDIUM5.4An authenticated stored cross-site scripting (XSS) vulnerability in Feehi CMS v2.1.1 allows attackers to execute arbitra...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now