2026 CVE Vulnerabilities

67,282 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33024CRITICAL9.1AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) ...
CVE-2026-33017CRITICAL9.8Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api...
CVE-2026-33013HIGH7.5Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat...
CVE-2026-33012HIGH7.5Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat...
CVE-2026-33011HIGH7.5Nest is a framework for building scalable Node.js server-side applications. In versions 11.1.15 and below, a NestJS appl...
CVE-2026-32954HIGH7.5ERP is a free and open source Enterprise Resource Planning tool. In versions prior to 16.8.0 and 15.100.0, certain endpo...
CVE-2026-32953MEDIUM4.6Tillitis TKey Client package is a Go package for a TKey client. Versions 1.2.0 and below contain a critical bug in the t...
CVE-2026-32950HIGH8.8SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a cr...
CVE-2026-32949HIGH7.5SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Se...
CVE-2026-32947MEDIUM4.9Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below,...
CVE-2026-4468MEDIUM4.7A vulnerability was determined in Comfast CF-AC100 2.6.0.8. Affected is an unknown function of the file /cgi-bin/mbox-co...
CVE-2026-4136MEDIUM4.3The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up t...
CVE-2026-4038CRITICAL9.8The Aimogen Pro plugin for WordPress is vulnerable to Arbitrary Function Call that can lead to privilege escalation due ...
CVE-2026-32946LOW2.7Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. In versions 2.15.1 and below,...
CVE-2026-32945CRITICAL9.8PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below have a Heap-based...
CVE-2026-32942HIGH8.1PJSIP is a free and open source multimedia communication library written in C. Versions 2.16 and below contain a heap u...
CVE-2026-32941MEDIUM6.5Sliver is a command and control framework that uses a custom Wireguard netstack. Versions 1.7.3 and below contain a Remo...
CVE-2026-32940MEDIUM6.1SiYuan is a personal knowledge management system. In versions 3.6.0 and below, SanitizeSVG has an incomplete blocklist —...
CVE-2026-32939HIGH8.1DataEase is an open source data visualization analysis tool. Versions 2.10.19 and below have inconsistent Locale handlin...
CVE-2026-32938MEDIUM6.5SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the deskto...
CVE-2026-32114MEDIUM4.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, there is a...
CVE-2026-4467MEDIUM4.7A vulnerability was found in Comfast CF-AC100 2.6.0.8. This impacts an unknown function of the file /cgi-bin/mbox-config...
CVE-2026-33063HIGH7.5free5GC is an open source 5G core network. free5GC AUSF prior to version 1.4.2 has is an Improper Null Check vulnerabili...
CVE-2026-33062HIGH7.5free5GC is an open source 5G core network. free5GC NRF prior to version 1.4.2 has an Improper Input Validation vulnerabi...
CVE-2026-32937MEDIUM6.5free5GC is an open source 5G core network. free5GC CHF prior to version 1.2.2 has an out-of-bounds slice access vulnerab...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now