2026 CVE Vulnerabilities

67,269 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-25086HIGH7.7Under certain conditions, an attacker could bind to the same port used by WebCTRL. This could allow the attacker to cra...
CVE-2026-24060CRITICAL9.1Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted,...
CVE-2026-4508HIGH7.3A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file ...
CVE-2026-3864MEDIUM6.5A vulnerability was discovered in the Kubernetes CSI Driver for NFS where the subDir parameter in volume identifiers was...
CVE-2026-33476HIGH7.5SiYuan is a personal knowledge management system. Prior to version 3.6.2, the Siyuan kernel exposes an unauthenticated f...
CVE-2026-33423MEDIUM4.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, staff can ...
CVE-2026-33422MEDIUM4.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the `ip_a...
CVE-2026-33411MEDIUM5.4Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a pote...
CVE-2026-33291MEDIUM5.4Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, moderators...
CVE-2026-33251MEDIUM5.4Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, an authori...
CVE-2026-33243HIGH8.2barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport t...
CVE-2026-33236HIGH8.1NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a...
CVE-2026-33231HIGH7.5NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a...
CVE-2026-33230MEDIUM6.1NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a...
CVE-2026-33228CRITICAL9.8flatted is a circular JSON parser. Prior to version 3.4.2, the parse() function in flatted can use attacker-controlled s...
CVE-2026-33226HIGH8.7Budibase is a low code platform for creating internal tools, workflows, and admin panels. In versions from 3.30.6 and pr...
CVE-2026-33221MEDIUM5.3Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.12.0, the storage service's file upload ha...
CVE-2026-33210CRITICAL9.1Ruby JSON is a JSON implementation for Ruby. From version 2.14.0 to before versions 2.15.2.1, 2.17.1.2, and 2.19.2, a fo...
CVE-2026-33209MEDIUM6.1Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.30.3, a reflected cross-site script...
CVE-2026-33204HIGH7.5SimpleJWT is a simple JSON web token library written in PHP. Prior to version 1.1.1, an unauthenticated attacker can per...
CVE-2026-33203HIGH7.5SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocket server accepts una...
CVE-2026-33194MEDIUM6.8SiYuan is a personal knowledge management system. Prior to version 3.6.2, the `IsSensitivePath()` function in `kernel/ut...
CVE-2026-33186CRITICAL9.1gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from ...
CVE-2026-33180HIGH7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio...
CVE-2026-32810MEDIUM5.5Halloy is an IRC application written in Rust. In versions on \*nix and macOS prior to commit f180e41061db393acf65bc99f5c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now