2026 CVE Vulnerabilities

66,812 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5182HIGH7.3A vulnerability was found in SourceCodester Teacher Record System 1.0. Impacted is an unknown function of the file Teach...
CVE-2026-34881MEDIUM5OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use...
CVE-2026-1877MEDIUM6.1The Auto Post Scheduler plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl...
CVE-2026-1834MEDIUM6.4The Ibtana – WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'...
CVE-2026-5181MEDIUM6.3A vulnerability has been found in SourceCodester Simple Doctors Appointment System up to 1.0. This issue affects some un...
CVE-2026-5180HIGH7.3A flaw has been found in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code o...
CVE-2026-5179HIGH7.3A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This affects an unknown part of th...
CVE-2026-4146MEDIUM6.1The Loco Translate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘update_href’ parameter ...
CVE-2026-1797MEDIUM5.3The Appointment Booking and Scheduler Plugin – Truebooker plugin for WordPress is vulnerable to Sensitive Information Ex...
CVE-2026-1710MEDIUM6.5The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data...
CVE-2026-5178HIGH8.8A security vulnerability has been detected in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this issue is the func...
CVE-2026-5177HIGH8.8A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this vulnerability is the function...
CVE-2026-34073MEDIUM5.3cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to version...
CVE-2026-34070HIGH7.5LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions i...
CVE-2026-34060CRITICAL9.8Ruby LSP is an implementation of the language server protocol for Ruby. Prior to Shopify.ruby-lsp version 0.10.2 and rub...
CVE-2026-34054HIGH7.8vcpkg is a free and open-source C/C++ package manager. Prior to version 3.6.1#3, vcpkg's Windows builds of OpenSSL set o...
CVE-2026-34043HIGH7.5Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, ther...
CVE-2026-34042HIGH8.2act is a project which allows for local running of github actions. Prior to version 0.2.86, act's built in actions/cache...
CVE-2026-34041CRITICAL9.8act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processe...
CVE-2026-34040HIGH7.8Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that all...
CVE-2026-34036MEDIUM6.5Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versio...
CVE-2026-33997HIGH8.1Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that all...
CVE-2026-32727MEDIUM6.5SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.7, the Enforcer is vulnerable ...
CVE-2026-32716MEDIUM6.5SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the Enforcer incorrectly va...
CVE-2026-32714CRITICAL9.8SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scito...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now