2026 CVE Vulnerabilities

67,057 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28505CRITICAL10Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() f...
CVE-2026-21717MEDIUM5.9A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash col...
CVE-2026-21716LOW3.3An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without th...
CVE-2026-21715LOW3.3A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read pe...
CVE-2026-21714MEDIUM5.3A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) t...
CVE-2026-21713MEDIUM5.9A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potent...
CVE-2026-21711MEDIUM5.3A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the req...
CVE-2026-21710HIGH7.5A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `_...
CVE-2026-5147HIGH7.3A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This affects an unknown part of the file /admin...
CVE-2026-3991HIGH7.8Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 M...
CVE-2026-3502HIGH7.8TrueConf Client downloads application update code and applies it without performing verification. An attacker who is abl...
CVE-2026-34714HIGH8.6Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configurat...
CVE-2026-29925HIGH7.7Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php.
CVE-2026-29924HIGH7.6Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the a...
CVE-2026-5126MEDIUM6.3A flaw has been found in SourceCodester RSS Feed Parser 1.0. Affected by this issue is the function file_get_contents. T...
CVE-2026-5125MEDIUM5.3A vulnerability was detected in raine consult-llm-mcp up to 2.5.3. Affected by this vulnerability is the function child_...
CVE-2026-4046HIGH7.5The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when convertin...
CVE-2026-33032CRITICAL9.8Nginx UI is a web user interface for the Nginx web server. In versions 2.3.5 and prior, the nginx-ui MCP (Model Context ...
CVE-2026-33030CRITICAL9.9Nginx UI is a web user interface for the Nginx web server. In versions 2.3.3 and prior, Nginx-UI contains an Insecure Di...
CVE-2026-33029MEDIUM6.5Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, an input validation vulnerability in ...
CVE-2026-33028HIGH7.5Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerabl...
CVE-2026-33027MEDIUM6.5Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly...
CVE-2026-30077HIGH7.5OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But ...
CVE-2026-29872HIGH8.2A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80...
CVE-2026-5124MEDIUM6.3A security vulnerability has been detected in osrg GoBGP up to 4.3.0. Affected is the function BGPHeader.DecodeFromBytes...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now