2026 CVE Vulnerabilities

67,225 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32948HIGH7.8sbt is a build tool for Scala, Java, and others. From version 0.9.5 to before version 1.12.7, on Windows, sbt uses Proce...
CVE-2026-22559HIGH8.8An Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the ac...
CVE-2026-21783MEDIUM4.3HCL Traveler is affected by sensitive information disclosure.  The application generates some error messages that provid...
CVE-2026-33769MEDIUM5.3Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path...
CVE-2026-33768CRITICAL9.1Astro is a web framework. Prior to version 10.0.2, the @astrojs/vercel serverless entrypoint reads the x-astro-path head...
CVE-2026-33627MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33624LOW2.7Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33539HIGH7.2Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33538HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33527MEDIUM4.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33508HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33498HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33429MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33421MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33417HIGH7.1Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in ...
CVE-2026-33409CRITICAL9.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33323MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-30932HIGH8.8Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessi...
CVE-2026-2417CRITICAL9.3A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version ...
CVE-2026-29772HIGH7.5Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full reque...
CVE-2026-23924MEDIUM4.9Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to t...
CVE-2026-23923MEDIUM5.3An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The...
CVE-2026-23921HIGH8.8A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiS...
CVE-2026-23920HIGH8.8Host and event action script input is validated with a regex (set by the administrator), but the validation runs in mult...
CVE-2026-23919MEDIUM6For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript repro...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now