2026 CVE Vulnerabilities

66,725 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34235CRITICAL9.1PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap out-of-boun...
CVE-2026-34231MEDIUM6.1Slippers is a UI component framework for Django. Prior to version 0.6.3, a Cross-Site Scripting (XSS) vulnerability exis...
CVE-2026-34227HIGH8.8Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click ...
CVE-2026-34221CRITICAL9.1MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions...
CVE-2026-34220CRITICAL9.8MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions...
CVE-2026-34219MEDIUM5.9libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Ru...
CVE-2026-34218MEDIUM6.3ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4....
CVE-2026-30284HIGH8.6An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical int...
CVE-2026-30281CRITICAL9.8An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files ...
CVE-2026-30276CRITICAL9.8An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical in...
CVE-2026-22569MEDIUM5.3An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amoun...
CVE-2026-22561HIGH7.8Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.336...
CVE-2026-4799MEDIUM4.3In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an unt...
CVE-2026-34532CRITICAL9.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34504HIGH8.3OpenClaw before 2026.3.28 contains a server-side request forgery vulnerability in the fal provider image-generation-prov...
CVE-2026-34503HIGH8.6OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked. ...
CVE-2026-34377HIGH8.1ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-consensus version 5.0.1, a logic...
CVE-2026-34373HIGH8.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34363MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34224MEDIUM4.4Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34214MEDIUM6.5Trino is a distributed SQL query engine for big data analytics. From version 439 to before version 480, Iceberg connecto...
CVE-2026-34210HIGH8.1mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the stripe/charge payment method ...
CVE-2026-34209HIGH7.5mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the tempo/session cooperative clo...
CVE-2026-34202HIGH7.5ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.0 and zebra-chain version 6.0.1, a vulnerabi...
CVE-2026-34200HIGH7.5Nhost is an open source Firebase alternative with GraphQL. Prior to version 1.41.0, The Nhost CLI MCP server, when expli...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now