2026 CVE Vulnerabilities

67,050 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32696HIGH7.5NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In NanoMQ version 0.24.6, after enabling auth.http...
CVE-2026-31946CRITICAL9.8OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. From vers...
CVE-2026-30313CRITICAL9.8DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitel...
CVE-2026-30308CRITICAL9.8In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe comman...
CVE-2026-30306CRITICAL9.8In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute al...
CVE-2026-28228HIGH8.8OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. Prior to ...
CVE-2026-27599HIGH7.2CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-27018HIGH7.5Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can ...
CVE-2026-25627HIGH7.5NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSoc...
CVE-2026-5150HIGH7.3A security vulnerability has been detected in code-projects Accounting System 1.0. This issue affects some unknown proce...
CVE-2026-5148MEDIUM4.7A weakness has been identified in YunaiV yudao-cloud up to 2026.01. This vulnerability affects unknown code of the file ...
CVE-2026-33026CRITICAL9.1Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui backup restore mechanism...
CVE-2026-32275CRITICAL9.1Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.1...
CVE-2026-31831HIGH7.5Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/...
CVE-2026-31804MEDIUM5.3Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_p...
CVE-2026-31799MEDIUM4.9Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 2.14.2 to before version 2.1...
CVE-2026-30307CRITICAL9.8Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelis...
CVE-2026-30305CRITICAL9.8Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist s...
CVE-2026-28505CRITICAL10Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() f...
CVE-2026-21717MEDIUM5.9A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash col...
CVE-2026-21716LOW3.3An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without th...
CVE-2026-21715LOW3.3A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read pe...
CVE-2026-21714MEDIUM5.3A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) t...
CVE-2026-21713MEDIUM5.9A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potent...
CVE-2026-21711MEDIUM5.3A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the req...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now