2026 CVE Vulnerabilities

67,183 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3116MEDIUM4.9Mattermost Plugins versions <=11.4 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to validate incoming request size which allows a...
CVE-2026-3115MEDIUM4.3Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restric...
CVE-2026-3114MEDIUM6.5Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompres...
CVE-2026-3113MEDIUM5.5Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on...
CVE-2026-3112MEDIUM4.9Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate Advanced ...
CVE-2026-3109LOW2.2Mattermost Plugins versions <=11.4 10.11.11.0 fail to validate webhook request timestamps which allows an attacker to co...
CVE-2026-3108HIGH8.8Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-cont...
CVE-2026-34071MEDIUM6.1Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. In version ...
CVE-2026-33636HIGH7.6LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2026-33470MEDIUM4.3Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, a low-...
CVE-2026-33469MEDIUM6.5Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In version 0.17.0, an aut...
CVE-2026-33468HIGH8.1Kysely is a type-safe TypeScript SQL query builder. Prior to version 0.28.14, Kysely's `DefaultQueryCompiler.sanitizeStr...
CVE-2026-33442HIGH8.1Kysely is a type-safe TypeScript SQL query builder. In versions 0.28.12 and 0.28.13, the `sanitizeStringLiteral` method ...
CVE-2026-33438MEDIUM6.5Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Versions st...
CVE-2026-33430HIGH7.3Briefcase is a tool for converting a Python project into a standalone native application. Starting in version 0.3.0 and ...
CVE-2026-33416HIGH7.5LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2026-33402MEDIUM6.1Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titl...
CVE-2026-33015MEDIUM5.2EVerest is an EV charging software stack. Prior to version 2026.02.0, even immediately after CSMS performs a RemoteStop ...
CVE-2026-33014MEDIUM5.2EVerest is an EV charging software stack. Prior to version 2026.02.0, during RemoteStop processing, a delayed authorizat...
CVE-2026-33009MEDIUM6.5EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to C++ UB (potential memo...
CVE-2026-32846HIGH7.5OpenClaw before 2026.3.28 contains a path traversal vulnerability in media parsing that allows attackers to read arbitra...
CVE-2026-29905MEDIUM6.5Kirby CMS through 5.1.4 allows an authenticated user with 'Editor' permissions to cause a persistent Denial of Service (...
CVE-2026-29044MEDIUM6.5EVerest is an EV charging software stack. Prior to version 2026.02.0, when WithdrawAuthorization is processed before the...
CVE-2026-27828HIGH7.5EVerest is an EV charging software stack. Prior to version 2026.02.0, ISO15118_chargerImpl::handle_session_setup uses v2...
CVE-2026-27816CRITICAL9.1EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_update_energy_tra...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now