2026 CVE Vulnerabilities

67,225 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33215MEDIUM6.5NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides...
CVE-2026-24159CRITICAL9.8NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A successful exploit o...
CVE-2026-24158HIGH7.5NVIDIA Triton Inference Server contains a vulnerability in the HTTP endpoint where an attacker may cause a denial of ser...
CVE-2026-24157CRITICAL9.8NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution...
CVE-2026-24152HIGH7.8NVIDIA Megatron-LM contains a vulnerability in checkpoint loading where an Attacker may cause an RCE by convincing a use...
CVE-2026-24151HIGH7.8NVIDIA Megatron-LM contains a vulnerability in inferencing where an Attacker may cause an RCE by convincing a user to lo...
CVE-2026-24150HIGH7.8NVIDIA Megatron-LM contains a vulnerability in checkpoint loading where an Attacker may cause an RCE by convincing a use...
CVE-2026-24141HIGH7.8NVIDIA Model Optimizer for Windows and Linux contains a vulnerability in the ONNX quantization feature, where a user cou...
CVE-2026-21790MEDIUM6.3HCL Traveler is susceptible to a weak default HTTP header validation vulnerability, which could allow an attacker to byp...
CVE-2026-33511CRITICAL9.8pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97...
CVE-2026-33509HIGH8.8pyLoad is a free and open-source download manager written in Python. From version 0.4.0 to before version 0.5.0b3.dev97,...
CVE-2026-33419HIGH7.5MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security T...
CVE-2026-33412HIGH7.3Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in ...
CVE-2026-33353MEDIUM6.5Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authoriza...
CVE-2026-33349MEDIUM5.9fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0....
CVE-2026-33347MEDIUM6.1league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in th...
CVE-2026-33345MEDIUM6.5solidtime is an open-source time-tracking app. Prior to version 0.11.6, the project detail endpoint GET /api/v1/organiza...
CVE-2026-33344HIGH8.1Dagu is a workflow engine with a built-in Web user interface. From version 2.0.0 to before version 2.3.1, the fix for CV...
CVE-2026-33332HIGH7.5NiceGUI is a Python-based UI framework. Prior to version 3.9.0, NiceGUI's app.add_media_file() and app.add_media_files()...
CVE-2026-33331MEDIUM5.4oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1....
CVE-2026-33330HIGH7.1FileRise is a self-hosted web file manager / WebDAV server. Prior to version 3.10.0, a broken access control issue in Fi...
CVE-2026-33329HIGH8.1FileRise is a self-hosted web file manager / WebDAV server. From version 1.0.1 to before version 3.10.0, the resumableId...
CVE-2026-33326MEDIUM4.3Keystone is a content management system for Node.js. Prior to version 6.5.2, {field}.isFilterable access control can be ...
CVE-2026-33322CRITICAL9.8MinIO is a high-performance object storage system. From RELEASE.2022-11-08T05-27-07Z to before RELEASE.2026-03-17T21-25-...
CVE-2026-33314MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to version 0.5.0b3.dev97, a Host Header Spoof...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now