2026 CVE Vulnerabilities

66,860 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33977MEDIUM6.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a malicious RDP server can cra...
CVE-2026-33952MEDIUM6.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, an unvalidated auth_length fie...
CVE-2026-32794MEDIUM4.8Improper Certificate Validation vulnerability in Apache Airflow Provider for Databricks. Provider code did not validate ...
CVE-2026-5152HIGH8.8A vulnerability was detected in Tenda CH22 1.0.0.1. Impacted is the function formCreateFileName of the file /goform/crea...
CVE-2026-4789CRITICAL9.8Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions.
CVE-2026-34558CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-34557CRITICAL9CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-32884MEDIUM5.9Botan is a C++ cryptography library. Prior to version 3.11.0, during processing of an X.509 certificate path using name ...
CVE-2026-32883MEDIUM5.9Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP resp...
CVE-2026-32877HIGH8.2Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that c...
CVE-2026-32696HIGH7.5NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In NanoMQ version 0.24.6, after enabling auth.http...
CVE-2026-31946CRITICAL9.8OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From vers...
CVE-2026-30313CRITICAL9.8DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitel...
CVE-2026-30308CRITICAL9.8In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe comman...
CVE-2026-30306CRITICAL9.8In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute al...
CVE-2026-28228HIGH8.8OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. Prior to ...
CVE-2026-27599HIGH7.2CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-27018HIGH7.5Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can ...
CVE-2026-25627HIGH7.5NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSoc...
CVE-2026-5150HIGH7.3A security vulnerability has been detected in code-projects Accounting System 1.0. This issue affects some unknown proce...
CVE-2026-5148MEDIUM4.7A weakness has been identified in YunaiV yudao-cloud up to 2026.01. This vulnerability affects unknown code of the file ...
CVE-2026-33026CRITICAL9.1Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism...
CVE-2026-32275CRITICAL9.1Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.1...
CVE-2026-31831HIGH7.5Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/...
CVE-2026-31804MEDIUM5.3Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_p...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now