2026 CVE Vulnerabilities

66,725 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-30282CRITICAL9An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwri...
CVE-2026-30279HIGH8.4An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overw...
CVE-2026-30278CRITICAL9.8An arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critica...
CVE-2026-30277HIGH8.4An arbitrary file overwrite vulnerability in PDF Reader App : TA/UTAX Mobile Print v3.7.2.251001 allows attackers to ove...
CVE-2026-2123HIGH7.8A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under speci...
CVE-2026-5205MEDIUM6.3A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigge...
CVE-2026-34361CRITICAL9.3HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio...
CVE-2026-34360MEDIUM5.8HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio...
CVE-2026-34359CRITICAL9.1HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio...
CVE-2026-24165HIGH8.8NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful explo...
CVE-2026-24164CRITICAL9.8NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful explo...
CVE-2026-24154MEDIUM6.8NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorre...
CVE-2026-24153MEDIUM5.5NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful ex...
CVE-2026-24148CRITICAL9.4NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker co...
CVE-2026-5204HIGH8.8A vulnerability was determined in Tenda CH22 1.0.0.1. Affected is the function formWebTypeLibrary of the file /goform/we...
CVE-2026-5203MEDIUM4.7A vulnerability was found in CMS Made Simple up to 2.2.22. This impacts the function _copyFilesToFolder in the library m...
CVE-2026-5087HIGH7.5PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for Perl generates random bytes insecurely. PAGI::Mi...
CVE-2026-4819MEDIUM6.5In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users log...
CVE-2026-4818HIGH8.1In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary priv...
CVE-2026-34595MEDIUM4.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34574MEDIUM5.4Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34573HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34243CRITICAL9.8wenxian is a tool to generate BIBTEX files from given identifiers (DOI, PMID, arXiv ID, or paper title). In versions 0.3...
CVE-2026-34240HIGH7.5JOSE is a Javascript Object Signing and Encryption (JOSE) library. Prior to version 0.3.5+1, a vulnerability in jose cou...
CVE-2026-34237MEDIUM6.1MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to versions 0.83.0, 1.0.1, a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now