2026 CVE Vulnerabilities

67,227 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33474MEDIUM6.5Vikunja is an open-source self-hosted task management platform. Starting in version 1.0.0-rc0 and prior to version 2.2.0...
CVE-2026-33473MEDIUM5.7Vikunja is an open-source self-hosted task management platform. Starting in version 0.13 and prior to version 2.2.1, any...
CVE-2026-33336HIGH8.8Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, t...
CVE-2026-33335HIGH8Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, t...
CVE-2026-33334CRITICAL9.6Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, t...
CVE-2026-29840MEDIUM5.4JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function within app...
CVE-2026-29839HIGH8.8DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php.
CVE-2026-4775HIGH7.8A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the ...
CVE-2026-33554HIGH7.5ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. The Intelligent Platform Manag...
CVE-2026-33316HIGH8.1Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, a flaw in Vikunja’s password res...
CVE-2026-33315MEDIUM4.3Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, the Caldav endpoint allows login...
CVE-2026-33313MEDIUM4.3Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.0, an authenticated user can read a...
CVE-2026-32647HIGH8.5NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module module, which might allow an attacker t...
CVE-2026-30662MEDIUM6.5ConcreteCMS v9.4.7 contains a Denial of Service (DoS) vulnerability in the File Manager component. The 'download' method...
CVE-2026-30661MEDIUM6.1iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within th...
CVE-2026-30655MEDIUM6.5SQL injection in Solicitante::resetaSenha() in esiclivre/esiclivre v0.2.2 and earlier allows unauthenticated remote atta...
CVE-2026-30653HIGH7.5An issue in Free5GC v.4.2.0 and before allows a remote attacker to cause a denial of service via the function HandleAuth...
CVE-2026-28755MEDIUM5.4NGINX Plus and NGINX Open Source have a vulnerability in the ngx_stream_ssl_module module due to the improper handling o...
CVE-2026-28753MEDIUM6.3NGINX Plus and NGINX Open Source have a vulnerability in the ngx_mail_smtp_module module due to the improper handling of...
CVE-2026-27784HIGH8.5The 32-bit implementation of NGINX Open Source has a vulnerability in the ngx_http_mp4_module module, which might allow ...
CVE-2026-27654HIGH8.8NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_dav_module module that might allow an attacker to ...
CVE-2026-27651HIGH8.7When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause ...
CVE-2026-33497HIGH7.5Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.7.1, in the download_p...
CVE-2026-33484HIGH7.5Langflow is a tool for building and deploying AI-powered agents and workflows. In versions 1.0.0 through 1.8.1, the `/ap...
CVE-2026-33418HIGH7.5DiceBear is an avatar library for designers and developers. Prior to version 9.4.2, the `ensureSize()` function in `@dic...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now