2026 CVE Vulnerabilities

66,494 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34831MEDIUM6.5Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Files#fail sets the Cont...
CVE-2026-34830HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Sendfile#map_accel_path ...
CVE-2026-34829HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser only w...
CVE-2026-34826HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.get_byte_ranges pa...
CVE-2026-34786MEDIUM5.3Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static#applicable_rules ...
CVE-2026-34785HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whethe...
CVE-2026-34763MEDIUM5.3Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Directory interpolates t...
CVE-2026-34230HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.select_best_encodi...
CVE-2026-34083MEDIUM6.1Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, SignalK Server co...
CVE-2026-33951HIGH7.5Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.1, the Signal...
CVE-2026-33950CRITICAL9.4Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0-beta.4, there is a...
CVE-2026-30603MEDIUM6.8An issue in the firmware update mechanism of Qianniao QN-L23PA0904 v20250721.1640 allows attackers to gain root access, ...
CVE-2026-26961MEDIUM5.3Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Multipart::Parser extrac...
CVE-2026-26895MEDIUM5.3User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames ...
CVE-2026-25212CRITICAL9.9An issue was discovered in Percona PMM before 3.7. Because an internal database user retains specific superuser privileg...
CVE-2026-5351HIGH8.8A weakness has been identified in Trendnet TEW-657BRM 1.00.1. This affects the function add_wps_client of the file /setu...
CVE-2026-5350HIGH8.8A security flaw has been discovered in Trendnet TEW-657BRM 1.00.1. The impacted element is the function update_pcdb of t...
CVE-2026-5349HIGH8.8A vulnerability was identified in Trendnet TEW-657BRM 1.00.1. The affected element is the function add_apcdb of the file...
CVE-2026-34876HIGH7.5An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in lib...
CVE-2026-33746CRITICAL9.8Convoy is a KVM server management panel for hosting businesses. From version 3.9.0-beta to before version 4.5.1, the JWT...
CVE-2026-33691HIGH7.5The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewal...
CVE-2026-30332HIGH7.5A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena Etcher for Windows prior to v2.1.4 allows...
CVE-2026-5346HIGH7.3A vulnerability was determined in huimeicloud hm_editor up to 2.2.3. Impacted is the function client.get of the file src...
CVE-2026-5344MEDIUM6.3A security vulnerability has been detected in Textpattern up to 4.9.1. Affected by this vulnerability is the function mt...
CVE-2026-5342MEDIUM5.5A flaw has been found in LibRaw up to 0.22.0. This affects the function LibRaw::nikon_load_padded_packed_raw of the file...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now