2026 CVE Vulnerabilities

67,167 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32285HIGH7.5The Delete function fails to properly validate offsets when processing malformed JSON input. This can lead to a negative...
CVE-2026-32284HIGH7.5The msgpack decoder fails to properly validate the input buffer length when processing truncated fixext data (format cod...
CVE-2026-2436HIGH8.2A flaw was found in libsoup's SoupServer. A remote attacker could exploit a use-after-free vulnerability where the `soup...
CVE-2026-4926HIGH7.5Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax...
CVE-2026-4923MEDIUM5.9Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that...
CVE-2026-3190MEDIUM4.3A flaw was found in Keycloak. The User-Managed Access (UMA) 2.0 Protection API endpoint for permission tickets fails to ...
CVE-2026-3121HIGH7.2A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where thi...
CVE-2026-33506HIGH8.8Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2.0 or OpenID Connect. Versio...
CVE-2026-33505HIGH7.2Ory Keto is am open source authorization server for managing permissions at scale. Prior to version 26.2.0, the GetRelat...
CVE-2026-33491HIGH7.8Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.4, a stack-based...
CVE-2026-33153MEDIUM6.5Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t...
CVE-2026-33152HIGH7.5Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t...
CVE-2026-33149HIGH8.1Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and ...
CVE-2026-33148MEDIUM6.5Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t...
CVE-2026-30463HIGH7.7Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php co...
CVE-2026-30458CRITICAL9.1An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitt...
CVE-2026-30457CRITICAL9.8An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via ...
CVE-2026-29969MEDIUM6.1A cross-site scripting (XSS) vulnerability in the wff_cols_pref.css.aspx endpoint of staffwiki v7.0.1.19219 allows attac...
CVE-2026-29055MEDIUM5.3Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t...
CVE-2026-28503MEDIUM6.5Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t...
CVE-2026-26213CRITICAL9.8thingino-firmware versions up to the firmware-2026-03-16 release contains an unauthenticated os command injection vulner...
CVE-2026-33732MEDIUM6.5srvx is a universal server based on web standards. Prior to version 0.11.13, a pathname parsing discrepancy in srvx's `F...
CVE-2026-33504HIGH7.2Ory Hydra is an OAuth 2.0 Server and OpenID Connect Provider. Prior to version 26.2.0, the listOAuth2Clients, listOAuth2...
CVE-2026-33503HIGH7.2Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 26.2.0, the Li...
CVE-2026-33496HIGH8.1ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now