2026 CVE Vulnerabilities

67,127 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3098MEDIUM6.5The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1...
CVE-2026-4909LOW2.4A weakness has been identified in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /...
CVE-2026-4908CRITICAL9.8A security flaw has been discovered in code-projects Simple Laundry System 1.0. This affects an unknown function of the ...
CVE-2026-4907MEDIUM6.3A vulnerability was identified in Page-Replica Page Replica up to e4a7f52e75093ee318b4d5a9a9db6751050d2ad0. The impacted...
CVE-2026-4906HIGH8.8A vulnerability was determined in Tenda AC5 15.03.06.47. The affected element is the function decodePwd of the file /gof...
CVE-2026-33935HIGH7.5MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated att...
CVE-2026-33890CRITICAL9.8MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated att...
CVE-2026-33747CRITICAL9.8BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P...
CVE-2026-33745HIGH7.4cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP ...
CVE-2026-33744HIGH7.8BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4....
CVE-2026-33735HIGH8.8MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypas...
CVE-2026-33730MEDIUM6.5Open Source Point of Sale (opensourcepos) is a web based point of sale application written in PHP using CodeIgniter fram...
CVE-2026-33729CRITICAL9.8OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z...
CVE-2026-33728CRITICAL9.8dd-trace-java is a Datadog APM client for Java. In versions of dd-trace-java 0.40.0 through prior to 1.60.2, the RMI ins...
CVE-2026-33726MEDIUM4.3Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.14, 1....
CVE-2026-33725HIGH7.2Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1...
CVE-2026-33721HIGH7.5MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a h...
CVE-2026-33718CRITICAL9.9OpenHands is software for AI-driven development. Starting in version 1.5.0, a Command Injection vulnerability exists in ...
CVE-2026-33701CRITICAL9.8OpenTelemetry Java Instrumentation provides OpenTelemetry auto-instrumentation and instrumentation libraries for Java. I...
CVE-2026-33699HIGH7.5pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.2 have a vulnerability in which an attack...
CVE-2026-33693MEDIUM6.5Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.7.0-beta.9, the `v4_is_invalid()` function in...
CVE-2026-4905HIGH8.8A vulnerability was found in Tenda AC5 15.03.06.47. Impacted is the function formWifiWpsOOB of the file /goform/WifiWpsO...
CVE-2026-4904HIGH8.8A vulnerability has been found in Tenda AC5 15.03.06.47. This issue affects the function formSetCfm of the file /goform/...
CVE-2026-33945CRITICAL9.6Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to system...
CVE-2026-33898HIGH8.8Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now