2026 CVE Vulnerabilities

67,363 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-61551HIGH8.6Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaus...
CVE-2026-61550CRITICAL9.8Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC mes...
CVE-2026-59163CRITICAL9.1Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_...
CVE-2026-33625HIGH8.8LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 conta...
CVE-2026-32641HIGH7.5Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.0.0, src/handlers/ht...
CVE-2026-93765CRITICAL9.1Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. In...
CVE-2026-93758HIGH8.1An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a ...
CVE-2026-93579MEDIUM6.5A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, s...
CVE-2026-93559HIGH7.3A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This aff...
CVE-2026-93534MEDIUM6.3A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file ap...
CVE-2026-93533MEDIUM6.3A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivi...
CVE-2026-93338MEDIUM5.3Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows una...
CVE-2026-91149HIGH7.5A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustain...
CVE-2026-91147MEDIUM5.9A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Serv...
CVE-2026-91142LOW3.6A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offse...
CVE-2026-85497CRITICAL9.8CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insu...
CVE-2026-85478LOW3.5A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical...
CVE-2026-81505HIGH7.1Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID}...
CVE-2026-81321CRITICAL9.8CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker w...
CVE-2026-77616MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77610MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77609MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77608MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77607MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77606MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now