2026 CVE Vulnerabilities

66,707 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-25833HIGH7.5Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function
CVE-2026-5199LOW2.3A writer role user in an attacker-controlled namespace could signal, delete, and reset workflows or activities in a vict...
CVE-2026-34875CRITICAL9.8An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key exp...
CVE-2026-34751CRITICAL9.1Payload is a free and open source headless content management system. Prior to version 3.79.1 in @payloadcms/graphql and...
CVE-2026-34447MEDIUM5.5Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, ...
CVE-2026-34446MEDIUM5.5Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, ...
CVE-2026-34445HIGH8.6Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, ...
CVE-2026-34397HIGH7Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From versions 2.0.0-alpha to before 2.3...
CVE-2026-34376HIGH7.5PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. Prior to...
CVE-2026-34236CRITICAL9.8Auth0-PHP is a PHP SDK for Auth0 Authentication and Management APIs. From version 8.0.0 to before version 8.19.0, in app...
CVE-2026-34222HIGH7.7Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8....
CVE-2026-34159CRITICAL9.8llama.cpp is an inference of several LLM models in C/C++. Prior to version b8492, the RPC backend's deserialize_tensor()...
CVE-2026-34076HIGH7.4Clerk JavaScript is the official JavaScript repository for Clerk authentication. In @clerk/hono from versions 0.1.0 to b...
CVE-2026-34072CRITICAL9.8Cr*nMaster (cronmaster) is a Cronjob management UI with human readable syntax, live logging and log history for cronjobs...
CVE-2026-27489HIGH7.5Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, ...
CVE-2026-25834MEDIUM6.5Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.
CVE-2026-5310LOW2.5A vulnerability was identified in Enter Software Iperius Backup up to 8.7.2. This impacts an unknown function of the fil...
CVE-2026-34604HIGH8.8Tina is a headless content management system. Prior to version 2.2.2, @tinacms/graphql uses string-based path containmen...
CVE-2026-34603HIGH8.3Tina is a headless content management system. Prior to version 2.2.2, @tinacms/cli recently added lexical path-traversal...
CVE-2026-33990CRITICAL9.1Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Prior to version 1.1.25, D...
CVE-2026-33978MEDIUM6.1Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerabilit...
CVE-2026-33949HIGH8.1Tina is a headless content management system. Prior to version 2.2.2, a path traversal vulnerability in @tinacms/graphql...
CVE-2026-30643CRITICAL9.8An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module u...
CVE-2026-30273HIGH7.3pandas-ai v3.0.0 was discovered to contain a SQL injection vulnerability via the pandasai.agent.base._execute_sql_query ...
CVE-2026-2265MEDIUM6.5An unauthenticated remote code execution (RCE) vulnerability exists in applications that use the Replicator node package...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now