2026 CVE Vulnerabilities

67,276 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33055HIGH8.1tar-rs is a tar archive reading/writing library for Rust. Versions 0.4.44 and below have conditional logic that skips th...
CVE-2026-33054CRITICAL9.8Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Pat...
CVE-2026-33053HIGH8.8Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the delete_ap...
CVE-2026-4473CRITICAL9.8A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. This issue affects some unknown proce...
CVE-2026-33051MEDIUM5.4Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu...
CVE-2026-33043HIGH8.1WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/phpsessionid.json.php exposes the cur...
CVE-2026-33041MEDIUM5.3WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/encryptPass.json.php exposes the appl...
CVE-2026-33040HIGH7.5libp2p-rust is the official rust language Implementation of the libp2p networking stack. In versions prior to 0.49.3, th...
CVE-2026-33039HIGH8.6WWBN AVideo is an open source video platform. In versions 25.0 and below, the plugin/LiveLinks/proxy.php endpoint valida...
CVE-2026-33038HIGH8.1WWBN AVideo is an open source video platform. Versions 25.0 and below are vulnerable to unauthenticated application take...
CVE-2026-33037HIGH8.1WWBN AVideo is an open source video platform. In versions 25.0 and below, the official Docker deployment files (docker-c...
CVE-2026-33036HIGH7.5fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-be...
CVE-2026-32768CRITICAL9.9Chall-Manager is a platform-agnostic system able to start Challenges on Demand of a player. In versions prior to 0.6.5, ...
CVE-2026-4472CRITICAL9.8A security vulnerability has been detected in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability a...
CVE-2026-4471CRITICAL9.8A weakness has been identified in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of ...
CVE-2026-4470CRITICAL9.8A security flaw has been discovered in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this issue is s...
CVE-2026-4469CRITICAL9.8A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. Affected by this vulnerability i...
CVE-2026-33035MEDIUM6.1WWBN AVideo is an open source video platform. In versions 25.0 and below, there is a reflected XSS vulnerability that al...
CVE-2026-33025HIGH8.8AVideo is a video-sharing Platform. Versions prior to 8.0 contain a SQL Injection vulnerability in the getSqlFromPost() ...
CVE-2026-33024CRITICAL9.1AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) ...
CVE-2026-33017CRITICAL9.8Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api...
CVE-2026-33013HIGH7.5Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat...
CVE-2026-33012HIGH7.5Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat...
CVE-2026-33011HIGH7.5Nest is a framework for building scalable Node.js server-side applications. In versions 11.1.15 and below, a NestJS appl...
CVE-2026-32954HIGH7.5ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now