2026 CVE Vulnerabilities

65,972 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34755MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO....
CVE-2026-34753MEDIUM5.4vLLM is an inference and serving engine for large language models (LLMs). From 0.16.0 to before 0.19.0, a server-side re...
CVE-2026-34589MEDIUM5OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-34588HIGH7.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-34444CRITICAL10Lupa integrates the runtimes of Lua or LuaJIT2 into CPython. In 2.6 and earlier, attribute_filter is not consistently ap...
CVE-2026-34402——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-39330. Reason: This candidate is a ...
CVE-2026-34380MEDIUM5.9OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-34379HIGH7.1OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-34378MEDIUM6.5OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-34217HIGH7.2SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, a scope modification vulnerability exists in @nyariv/sand...
CVE-2026-34211HIGH7.5SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, the @nyariv/sandboxjs parser contains unbounded recursion...
CVE-2026-34208CRITICAL10SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, SandboxJS blocks direct assignment to global objects (for...
CVE-2026-34148HIGH7.5Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8,...
CVE-2026-33752HIGH8.6curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges,...
CVE-2026-33727MEDIUM6.7Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Version 6.4 has a local privil...
CVE-2026-33405MEDIUM4.8Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic...
CVE-2026-31354MEDIUM5.4Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 a...
CVE-2026-31353MEDIUM5.4An authenticated stored cross-site scripting (XSS) vulnerability in the Category module of Feehi CMS v2.1.1 allows attac...
CVE-2026-31352MEDIUM5.4An authenticated stored cross-site scripting (XSS) vulnerability in the Role Management module of Feehi CMS v2.1.1 allow...
CVE-2026-31351MEDIUM4.8An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allo...
CVE-2026-31350MEDIUM5.4An authenticated stored cross-site scripting (XSS) vulnerability in Feehi CMS v2.1.1 allows attackers to execute arbitra...
CVE-2026-21382HIGH7.8Memory Corruption when handling power management requests with improperly sized input/output buffers.
CVE-2026-21381HIGH7.5Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood aware...
CVE-2026-21380HIGH7.8Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.
CVE-2026-21378HIGH7.8Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now