2026 CVE Vulnerabilities

67,331 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32829HIGH7.5lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0, deco...
CVE-2026-32828MEDIUM4.9Kargo manages and automates the promotion of software artifacts. In versions 1.4.0 through 1.6.3, 1.7.0-rc.1 through 1.7...
CVE-2026-32771CRITICAL9.8The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, met...
CVE-2026-32769CRITICAL9.8Fullchain is an umbrella project for deploying a ready-to-use CTF platform. In versions prior to 0.1.1, due to a mis-wr...
CVE-2026-32767CRITICAL9.8SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability...
CVE-2026-33289CRITICAL9.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-33288HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-32985CRITICAL9.8Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the te...
CVE-2026-32766MEDIUM5.3astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.6 and earlier, malformed PAX e...
CVE-2026-32765——Rejected reason: This repository is no longer public.
CVE-2026-32764——Rejected reason: This repository is no longer public.
CVE-2026-32763HIGH8.2Kysely is a type-safe TypeScript SQL query builder. Versions up to and including 0.28.11 has a SQL injection vulnerabili...
CVE-2026-32761MEDIUM6.5File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-32760CRITICAL9.8File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-32759HIGH8.1File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-32758MEDIUM6.5File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-32757MEDIUM5.4Admidio is an open-source user management solution. In versions 5.0.6 and below, the eCard send handler uses a raw $_POS...
CVE-2026-32756HIGH8.8Admidio is an open-source user management solution. Versions 5.0.6 and below contain a critical unrestricted file upload...
CVE-2026-32697MEDIUM6.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29189HIGH8.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29109HIGH7.2SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions up to...
CVE-2026-29108MEDIUM6.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-22737MEDIUM5.9Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications c...
CVE-2026-22735LOW2.6Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue ...
CVE-2026-22733HIGH8.1Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now