2026 CVE Vulnerabilities

66,169 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-35030CRITICAL9.4LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, when JWT authenti...
CVE-2026-35029HIGH8.8LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/updat...
CVE-2026-34992HIGH7.5Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to 2.4.5 and 2.5.2, a missing encrypt...
CVE-2026-34989CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-34986HIGH7.5Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including sup...
CVE-2026-34981MEDIUM5.8The whisperX API is a tool for enhancing and analyzing audio content. From 0.3.1 to 0.5.0, FileService.download_from_url...
CVE-2026-34977CRITICAL9.8Aperi'Solve is an open-source steganalysis web platform. In versions 3.1.3 through 3.2.0, when uploading a JPEG, a user ...
CVE-2026-34976CRITICAL10Dgraph is an open source distributed GraphQL database. Prior to 25.3.1, the restoreTenant admin mutation is missing from...
CVE-2026-34975MEDIUM4.3Plunk is an open-source email platform built on top of AWS SES. Prior to 0.8.0, a CRLF header injection vulnerability wa...
CVE-2026-34841CRITICAL9.8Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack ...
CVE-2026-34783HIGH8.1Ferret is a declarative system for working with web data. Prior to 2.0.0-alpha.4, a path traversal vulnerability in Ferr...
CVE-2026-31313MEDIUM5.4An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allo...
CVE-2026-5704MEDIUM5.5A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to ...
CVE-2026-5666MEDIUM5.5A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionalit...
CVE-2026-5665HIGH7.3A security vulnerability has been detected in code-projects Online FIR System 1.0. Affected by this vulnerability is an ...
CVE-2026-34982HIGH8.2Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbi...
CVE-2026-34969HIGH7.5Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback f...
CVE-2026-34951MEDIUM6.1Workbench is a suite of tools for administrators and developers to interact with Salesforce.com organizations via the Fo...
CVE-2026-34950CRITICAL9.1fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-...
CVE-2026-34940HIGH8.8KubeAI is an AI inference operator for kubernetes. Prior to 0.23.2, the ollamaStartupProbeScript() function in internal/...
CVE-2026-34764MEDIUM5.5Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 33.0.0-alph...
CVE-2026-34756MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Servi...
CVE-2026-34755MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO....
CVE-2026-34753MEDIUM5.4vLLM is an inference and serving engine for large language models (LLMs). From 0.16.0 to before 0.19.0, a server-side re...
CVE-2026-34589MEDIUM5OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now