2026 CVE Vulnerabilities

67,227 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-23920HIGH8.8Host and event action script input is validated with a regex (set by the administrator), but the validation runs in mult...
CVE-2026-23919MEDIUM6For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript repro...
CVE-2026-1995HIGH7.8In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from seve...
CVE-2026-33407CRITICAL9.1Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/se...
CVE-2026-33401MEDIUM6.5Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the patch introduced in c...
CVE-2026-33400MEDIUM5.4Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, a stored cross-site scrip...
CVE-2026-33399HIGH7.7Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in v...
CVE-2026-33162MEDIUM6.5Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control pa...
CVE-2026-33161MEDIUM4.3Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R...
CVE-2026-33160MEDIUM5.3Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R...
CVE-2026-33159MEDIUM6.5Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R...
CVE-2026-33158MEDIUM6.5Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R...
CVE-2026-33157HIGH7.2Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.13, a Remote Code Execution (RC...
CVE-2026-32854HIGH7.5LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the...
CVE-2026-32853HIGH8.1LibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a heap out-of-bounds read vulnerability in the ...
CVE-2026-26809——Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-33340CRITICAL9.1LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side ...
CVE-2026-33700MEDIUM4.9Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DELETE /api/v1/projects/:pr...
CVE-2026-33680MEDIUM6.5Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.2, the `LinkSharing.ReadAll()` meth...
CVE-2026-33679HIGH7.4Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DownloadImage` function in ...
CVE-2026-33678HIGH8.1Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, `TaskAttachment.ReadOne()` queri...
CVE-2026-33677MEDIUM6.5Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `GET /api/v1/projects/:proje...
CVE-2026-33676MEDIUM6.5Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, when the Vikunja API returns tas...
CVE-2026-33675MEDIUM5.4Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the migration helper functions `...
CVE-2026-33668HIGH8.1Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, w...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now