2026 CVE Vulnerabilities

67,127 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33640CRITICAL9.8Outline is a service that allows for collaborative documentation. Outline implements an Email OTP login flow for users n...
CVE-2026-33638MEDIUM5.3Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to version 4.2.0, `GET /api/all...
CVE-2026-33635MEDIUM4.3iCalendar is a Ruby library for dealing with iCalendar files in the iCalendar format defined by RFC-5545. Starting in ve...
CVE-2026-33628MEDIUM5.4Invoice Ninja is a source-available invoice, quote, project and time-tracking app built with Laravel. Invoice line item ...
CVE-2026-33623HIGH7.2PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.4` contai...
CVE-2026-33622HIGH8.8PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.3` throug...
CVE-2026-33621MEDIUM6.5PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.7` throug...
CVE-2026-33620MEDIUM4.3PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.8` throug...
CVE-2026-33619MEDIUM5.5PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab v0.8.3 contains...
CVE-2026-33545MEDIUM6.5MobSF is a mobile application security testing tool used. Prior to version 4.4.6, MobSF's `read_sqlite()` function in `m...
CVE-2026-33541MEDIUM6.5TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigati...
CVE-2026-33537MEDIUM5Lychee is a free, open-source photo-management tool. The patch introduced for GHSA-cpgw-wgf3-xc6v (SSRF via `Photo::from...
CVE-2026-33375MEDIUM6.5The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API rest...
CVE-2026-2272MEDIUM6.5A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the ...
CVE-2026-2271MEDIUM5.5A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnera...
CVE-2026-2239MEDIUM6.5A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing ...
CVE-2026-2100HIGH7.5A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a...
CVE-2026-21724MEDIUM4.3A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API ...
CVE-2026-0968LOW3.1A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a m...
CVE-2026-0967MEDIUM5.5A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could cra...
CVE-2026-0966HIGH8.2A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-...
CVE-2026-0965LOW3.3A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker c...
CVE-2026-0964MEDIUM6.3A malicious SCP server can send unexpected paths that could make the client application override local files outside of ...
CVE-2026-33632HIGH7.8ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4....
CVE-2026-33631HIGH8.7ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. In versions on the ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now