2026 CVE Vulnerabilities

67,100 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4248HIGH8The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and incl...
CVE-2026-33996MEDIUM5.5LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS ...
CVE-2026-33994CRITICAL9.8Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Starting in version 2.0.39...
CVE-2026-33993CRITICAL9.8Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.25, t...
CVE-2026-33992MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, PyLoad's download e...
CVE-2026-33991HIGH8.8WeGIA is a web manager for charitable institutions. Prior to version 3.6.7, the file `html/socio/sistema/deletar_tag.php...
CVE-2026-33936MEDIUM5.3The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (El...
CVE-2026-4990HIGH7.3A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the ...
CVE-2026-4988MEDIUM5.9A security flaw has been discovered in Open5GS 2.7.6. This issue affects the function smf_gx_cca_cb/smf_gy_cca_cb/smf_s6...
CVE-2026-4985MEDIUM5.3A vulnerability was identified in dloebl CGIF up to 0.5.2. This vulnerability affects the function cgif_addframe of the ...
CVE-2026-34226HIGH7.5Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Versions prior to 20.8.9...
CVE-2026-33989MEDIUM6.5Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp...
CVE-2026-33981MEDIUM6.5changedetection.io is a free open source web page change detection tool. Prior to 0.54.7, the `jq:` and `jqraw:` include...
CVE-2026-33980HIGH8.1Azure Data Explorer MCP Server is a Model Context Protocol (MCP) server that enables AI assistants to execute KQL querie...
CVE-2026-33979HIGH8.2Express XSS Sanitizer is Express 4.x and 5.x middleware which sanitizes user input data (in req.body, req.query, req.hea...
CVE-2026-33976CRITICAL9.6Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the We...
CVE-2026-33955HIGH8.6Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in t...
CVE-2026-33954MEDIUM6.5LinkAce is a self-hosted archive to collect website links. In versions prior to 2.5.3, a private note attached to a non-...
CVE-2026-33953HIGH8.5LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP l...
CVE-2026-33946MEDIUM5.9MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby S...
CVE-2026-33943CRITICAL9.8Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 thro...
CVE-2026-33941HIGH8.2Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Hand...
CVE-2026-33940HIGH8.1Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafte...
CVE-2026-33939HIGH7.5Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a H...
CVE-2026-27309HIGH7.8Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now