2026 CVE Vulnerabilities

66,601 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32871CRITICAL10FastMCP is a Pythonic way to build MCP servers and clients. Prior to version 3.2.0, the OpenAPIProvider in FastMCP expos...
CVE-2026-32629MEDIUM6.1phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, an unauthenticated attacker can submit a guest F...
CVE-2026-31937HIGH7.5Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a p...
CVE-2026-31935HIGH7.5Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, flooding of craft HTTP2 continuation ...
CVE-2026-31934HIGH7.5Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexi...
CVE-2026-5338HIGH7.2A security vulnerability has been detected in Tenda G103 1.0.0.5. The affected element is the function action_set_system...
CVE-2026-5334CRITICAL9.8A weakness has been identified in itsourcecode Online Enrollment System 1.0. Impacted is an unknown function of the file...
CVE-2026-5333CRITICAL9.8A security flaw has been discovered in DefaultFuction Content-Management-System 1.0. This issue affects some unknown pro...
CVE-2026-5332MEDIUM6.1A vulnerability was identified in Xiaopi Panel 1.0.0. This vulnerability affects unknown code of the file /demo.php of t...
CVE-2026-3692HIGH8.8In Progress Flowmon versions prior to 12.5.8, a vulnerability exists whereby an authenticated low-privileged user may cr...
CVE-2026-35168HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, th...
CVE-2026-31933HIGH7.5Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause S...
CVE-2026-31932HIGH7.5Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can le...
CVE-2026-31931HIGH7.5Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, use of the "tls.alpn" rule ke...
CVE-2026-30867MEDIUM6.5CocoaMQTT is a MQTT 5.0 client library for iOS and macOS written in Swift. Prior to version 2.2.2, a vulnerability exist...
CVE-2026-2737MEDIUM6.1A vulnerability exists in Progress Flowmon versions prior to 12.5.8 and 13.0.6, whereby an administrator who clicks a ma...
CVE-2026-2701HIGH8.8Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
CVE-2026-2699CRITICAL9.8Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted config...
CVE-2026-29782HIGH7.2OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, th...
CVE-2026-28805HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, mu...
CVE-2026-26928HIGH8.7SzafirHost downloads necessary files in the context of the initiating web page. When called, SzafirHost updates its dyna...
CVE-2026-26927MEDIUM5.1Szafir SDK Web is a browser plug-in that can run SzafirHost application which download the necessary files when launched...
CVE-2026-5331MEDIUM4.7A vulnerability was determined in OpenCart 4.1.0.3. This affects an unknown part of the file installer.php of the compon...
CVE-2026-5330MEDIUM6.5A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some ...
CVE-2026-5328MEDIUM6.3A weakness has been identified in shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6. The impacted e...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now