2026 CVE Vulnerabilities

67,274 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33203HIGH7.5SiYuan is a personal knowledge management system. Prior to version 3.6.2, the SiYuan kernel WebSocket server accepts una...
CVE-2026-33194MEDIUM6.8SiYuan is a personal knowledge management system. Prior to version 3.6.2, the `IsSensitivePath()` function in `kernel/ut...
CVE-2026-33186CRITICAL9.1gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from ...
CVE-2026-33180HIGH7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to versio...
CVE-2026-32810MEDIUM5.5Halloy is an IRC application written in Rust. In versions on \*nix and macOS prior to commit f180e41061db393acf65bc99f5c...
CVE-2026-32733MEDIUM6.5Halloy is an IRC application written in Rust. Prior to commit 0f77b2cfc5f822517a256ea5a4b94bad8bfe38b6, the DCC receive ...
CVE-2026-32663MEDIUM6.5The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ...
CVE-2026-31926MEDIUM6.9Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-31904HIGH8.7The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc...
CVE-2026-31903HIGH8.7The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc...
CVE-2026-2598——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-29796CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat...
CVE-2026-28204MEDIUM6.9Charging station authentication identifiers are publicly accessible via web-based mapping platforms.
CVE-2026-27649MEDIUM6.5The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ...
CVE-2026-25192CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonat...
CVE-2026-22163HIGH7.8Requires malware code to misuse the DDK kernel module IOCTL interface. Such code can use the interface in an unsupporte...
CVE-2026-21732CRITICAL9.6A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-...
CVE-2026-4507MEDIUM6.3A vulnerability was determined in Mindinventory MindSQL up to 0.2.1. The affected element is the function ask_db of the ...
CVE-2026-4506MEDIUM6.3A vulnerability was found in Mindinventory MindSQL up to 0.2.1. Impacted is the function ask_db of the file mindsql/core...
CVE-2026-3584CRITICAL9.8The Kali Forms plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.9 v...
CVE-2026-33177MEDIUM4.3Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, low-privileg...
CVE-2026-33172HIGH8.7Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS...
CVE-2026-33171MEDIUM4.3Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, authenticate...
CVE-2026-33166HIGH7.5Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. The Allure report generator p...
CVE-2026-32887HIGH7.4Effect is a TypeScript framework that consists of several packages that work together to help build TypeScript applicati...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now