2026 CVE Vulnerabilities

67,167 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33541MEDIUM6.5TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigati...
CVE-2026-33537MEDIUM5Lychee is a free, open-source photo-management tool. The patch introduced for GHSA-cpgw-wgf3-xc6v (SSRF via `Photo::from...
CVE-2026-33375MEDIUM6.5The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API rest...
CVE-2026-2272MEDIUM6.5A flaw was found in GIMP. An integer overflow vulnerability exists when processing ICO image files, specifically in the ...
CVE-2026-2271MEDIUM5.5A flaw was found in GIMP's PSP (Paint Shop Pro) file parser. A remote attacker could exploit an integer overflow vulnera...
CVE-2026-2239MEDIUM6.5A flaw was found in GIMP. Heap-buffer-overflow vulnerability exists in the fread_pascal_string function when processing ...
CVE-2026-2100HIGH7.5A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a...
CVE-2026-21724MEDIUM4.3A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API ...
CVE-2026-0968LOW3.1A flaw was found in libssh in which a malicious SFTP (SSH File Transfer Protocol) server can exploit this by sending a m...
CVE-2026-0967MEDIUM5.5A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could cra...
CVE-2026-0966HIGH8.2A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-...
CVE-2026-0965LOW3.3A flaw was found in libssh where it can attempt to open arbitrary files during configuration parsing. A local attacker c...
CVE-2026-0964MEDIUM6.3A malicious SCP server can send unexpected paths that could make the client application override local files outside of ...
CVE-2026-33632HIGH7.8ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4....
CVE-2026-33631HIGH8.7ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. In versions on the ...
CVE-2026-33536MEDIUM4.7ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9...
CVE-2026-33535MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-18 and 6.9...
CVE-2026-33532MEDIUM4.3`yaml` is a YAML parser and serialiser for JavaScript. Parsing a YAML document with a version of `yaml` on the 1.x branc...
CVE-2026-33531MEDIUM6.5InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, a path traversal vulnerability in the r...
CVE-2026-33530MEDIUM6.5InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with b...
CVE-2026-33529HIGH8.8Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. Prior to version 3.3.2, an authenticated path traver...
CVE-2026-33528MEDIUM6.5GoDoxy is a reverse proxy and container orchestrator for self-hosters. Prior to version 0.27.5, the file content API end...
CVE-2026-33525MEDIUM6.1Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o...
CVE-2026-32287HIGH7.5Boolean XPath expressions that evaluate to true can cause an infinite loop in logicalQuery.Select, leading to 100% CPU u...
CVE-2026-32286HIGH7.5The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can s...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now