2026 CVE Vulnerabilities

67,127 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33536MEDIUM4.7ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9...
CVE-2026-33535MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9...
CVE-2026-33532MEDIUM4.3`yaml` is a YAML parser and serialiser for JavaScript. Parsing a YAML document with a version of `yaml` on the 1.x branc...
CVE-2026-33531MEDIUM6.5InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the r...
CVE-2026-33530MEDIUM6.5InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with b...
CVE-2026-33529HIGH8.8Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. Prior to version 3.3.2, an authenticated path traver...
CVE-2026-33528MEDIUM6.5GoDoxy is a reverse proxy and container orchestrator for self-hosters. Prior to version 0.27.5, the file content API end...
CVE-2026-33525MEDIUM6.1Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o...
CVE-2026-32287HIGH7.5Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU u...
CVE-2026-32286HIGH7.5The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can s...
CVE-2026-32285HIGH7.5The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative...
CVE-2026-32284HIGH7.5The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format cod...
CVE-2026-2436HIGH8.2A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup...
CVE-2026-4926HIGH7.5Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax...
CVE-2026-4923MEDIUM5.9Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that...
CVE-2026-3190MEDIUM4.3A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to ...
CVE-2026-3121HIGH7.2A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where thi...
CVE-2026-33506HIGH8.8Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versio...
CVE-2026-33505HIGH7.2Ory Keto is am open source authorization server for managing permissions at scale. Prior to version 26.2.0, the GetRelat...
CVE-2026-33491HIGH7.8Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.4, a stack-based...
CVE-2026-33153MEDIUM6.5Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t...
CVE-2026-33152HIGH7.5Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t...
CVE-2026-33149HIGH8.1Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and ...
CVE-2026-33148MEDIUM6.5Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t...
CVE-2026-30463HIGH7.7Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php co...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now