2026 CVE Vulnerabilities

67,109 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33955HIGH8.6Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in t...
CVE-2026-33954MEDIUM6.5LinkAce is a self-hosted archive to collect website links. In versions prior to 2.5.3, a private note attached to a non-...
CVE-2026-33953HIGH8.5LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP l...
CVE-2026-33946MEDIUM5.9MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby S...
CVE-2026-33943CRITICAL9.8Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 thro...
CVE-2026-33941HIGH8.2Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Hand...
CVE-2026-33940HIGH8.1Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafte...
CVE-2026-33939HIGH7.5Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a H...
CVE-2026-27309HIGH7.8Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbi...
CVE-2026-4976HIGH8.8A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestC...
CVE-2026-34046HIGH8.8Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow` ...
CVE-2026-33938HIGH8.1Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@pa...
CVE-2026-33937CRITICAL9.8Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handleb...
CVE-2026-33916MEDIUM4.7Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `resolve...
CVE-2026-33907MEDIUM6.5Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing Authentication Respo...
CVE-2026-33906HIGH7.2Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup...
CVE-2026-33904MEDIUM6.5Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, a deadlock in the AMF's SCTP notification ...
CVE-2026-33903MEDIUM6.5Ella Core is a 5G core designed for private networks. Versions prior to 1.7.0 panic when processing a specially crafted ...
CVE-2026-33896CRITICAL9.1Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ...
CVE-2026-33895HIGH7.5Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ...
CVE-2026-33894HIGH7.5Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ...
CVE-2026-33891HIGH7.5Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ...
CVE-2026-33887MEDIUM5.4Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, authenticate...
CVE-2026-33886MEDIUM6.5Statamic is a Laravel and Git powered content management system (CMS). Starting in version 5.7.12 and prior to versions ...
CVE-2026-33885MEDIUM6.1Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now