2026 CVE Vulnerabilities

67,274 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32595LOW3.7Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea...
CVE-2026-32305MEDIUM5.3Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea...
CVE-2026-25792MEDIUM6.5Greenshot is an open source Windows screenshot utility. Versions 1.3.312 and below have untrusted executable search path...
CVE-2026-33130MEDIUM6.5Uptime Kuma is an open source, self-hosted monitoring tool. In versions 1.23.0 through 2.2.0, the fix from GHSA-vffh-c9p...
CVE-2026-33129MEDIUM5.9H3 is a minimal H(TTP) framework. Versions 2.0.1-beta.0 through 2.0.0-rc.8 contain a Timing Side-Channel vulnerability i...
CVE-2026-33128CRITICAL10H3 is a minimal H(TTP) framework. In versions prior to 1.15.6 and between 2.0.0 through 2.0.1-rc.14, createEventStream i...
CVE-2026-33125HIGH8.1Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. In versions 0.16.2 and be...
CVE-2026-33124HIGH8.8Frigate is a network video recorder (NVR) with realtime local object detection for IP cameras. Versions prior to 0.17.0-...
CVE-2026-33123MEDIUM6.5pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious ...
CVE-2026-33081LOW3.7PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Versions 0.8.2 and below...
CVE-2026-22324HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-0677MEDIUM6.3Deserialization of Untrusted Data vulnerability in TotalSuite TotalContest Lite totalcontest-lite allows Object Injectio...
CVE-2026-3550MEDIUM5.3The RockPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.17. ...
CVE-2026-33192MEDIUM5.3Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. In versions prior to 1....
CVE-2026-33080MEDIUM5.4Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.8.4 and ...
CVE-2026-33075HIGH8.8FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vuln...
CVE-2026-33072HIGH7.5FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.9.0, a hardcoded default encryption k...
CVE-2026-33071HIGH8.8FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, the WebDAV upload endpoint accep...
CVE-2026-33070MEDIUM4.8FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, a missing-authentication vulnera...
CVE-2026-33069HIGH7.5PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a cascading ...
CVE-2026-33068HIGH8.8Claude Code is an agentic coding tool. Versions prior to 2.1.53 resolved the permission mode from settings files, includ...
CVE-2026-33067CRITICAL9SiYuan is a personal knowledge management system. Versions 3.6.0 and below render package metadata fields (displayName, ...
CVE-2026-33066CRITICAL9SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the backend renderREADME function uses lu...
CVE-2026-32701HIGH7.5Qwik is a performance-focused JavaScript framework. Versions prior to 1.19.2 improperly inferred arrays from dotted form...
CVE-2026-2432MEDIUM4.4The CM Custom Reports – Flexible reporting to track what matters most plugin for WordPress is vulnerable to Stored Cross...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now