2026 CVE Vulnerabilities

67,183 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33491HIGH7.8Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.4, a stack-based...
CVE-2026-33153MEDIUM6.5Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t...
CVE-2026-33152HIGH7.5Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t...
CVE-2026-33149HIGH8.1Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Versions up to and ...
CVE-2026-33148MEDIUM6.5Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t...
CVE-2026-30463HIGH7.7Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php co...
CVE-2026-30458CRITICAL9.1An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitt...
CVE-2026-30457CRITICAL9.8An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via ...
CVE-2026-29969MEDIUM6.1A cross-site scripting (XSS) vulnerability in the wff_cols_pref.css.aspx endpoint of staffwiki v7.0.1.19219 allows attac...
CVE-2026-29055MEDIUM5.3Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t...
CVE-2026-28503MEDIUM6.5Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t...
CVE-2026-26213CRITICAL9.8thingino-firmware versions up to the firmware-2026-03-16 release contains an unauthenticated os command injection vulner...
CVE-2026-33732MEDIUM6.5srvx is a universal server based on web standards. Prior to version 0.11.13, a pathname parsing discrepancy in srvx's `F...
CVE-2026-33504HIGH7.2Ory Hydra is an OAuth 2.0 Server and OpenID Connect Provider. Prior to version 26.2.0, the listOAuth2Clients, listOAuth2...
CVE-2026-33503HIGH7.2Ory Kratos is an identity, user management and authentication system for cloud services. Prior to version 26.2.0, the Li...
CVE-2026-33496HIGH8.1ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o...
CVE-2026-33495MEDIUM6.5ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o...
CVE-2026-33494CRITICAL10ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o...
CVE-2026-33490MEDIUM5.3H3 is a minimal H(TTP) framework. In versions 2.0.0-0 through 2.0.1-rc.16, the `mount()` method in h3 uses a simple `sta...
CVE-2026-33487HIGH7.5goxmlsig provides XML Digital Signatures implemented in Go. Prior to version 1.6.0, the `validateSignature` function in ...
CVE-2026-33486MEDIUM6.5Roadiz is a polymorphic content management system based on a node system that can handle many types of services. A vulne...
CVE-2026-33481MEDIUM5.3Syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesys...
CVE-2026-33477MEDIUM4.3FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In versiosn 2.3....
CVE-2026-32857HIGH8.6Firecrawl version 2.8.0 and prior contain a server-side request forgery (SSRF) protection bypass vulnerability in the Pl...
CVE-2026-4867HIGH7.5Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now