2026 CVE Vulnerabilities

67,413 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-92745MEDIUM5A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process met...
CVE-2026-92702CRITICAL9.1Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions ...
CVE-2026-92701CRITICAL9.1Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions ...
CVE-2026-91127HIGH8.2File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applic...
CVE-2026-85058HIGH7.5Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last W...
CVE-2026-84992MEDIUM6.1md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt()...
CVE-2026-84975HIGH7.4PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuT...
CVE-2026-81182MEDIUM4.2SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a ...
CVE-2026-81181LOW3.7SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for pro...
CVE-2026-81180HIGH8.8SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Profess...
CVE-2026-81179HIGH8.1SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset...
CVE-2026-81178LOW3.5SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public no...
CVE-2026-77396MEDIUM6.9PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser...
CVE-2026-77386MEDIUM6.5Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker cou...
CVE-2026-77385MEDIUM4.3Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core...
CVE-2026-71537MEDIUM6.5Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Se...
CVE-2026-69186MEDIUM5.3c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NS...
CVE-2026-69184HIGH7.5c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression poi...
CVE-2026-64847MEDIUM6.8AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Pri...
CVE-2026-63458HIGH7.1Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenti...
CVE-2026-63445HIGH7.1Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoint...
CVE-2026-63199HIGH8.3Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the ...
CVE-2026-62279HIGH7.1LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an aut...
CVE-2026-62278HIGH8.1LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authen...
CVE-2026-61552HIGH7.2Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes atta...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now