2026 CVE Vulnerabilities

67,335 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-29108MEDIUM6.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-22737MEDIUM5.9Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications c...
CVE-2026-22735LOW2.6Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue ...
CVE-2026-22733HIGH8.1Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application...
CVE-2026-3948——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-33408LOW2.7Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, moderators...
CVE-2026-33395MEDIUM5.4Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the discou...
CVE-2026-32818MEDIUM6.5Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the forum module in Admidio does no...
CVE-2026-32816MEDIUM5.7Admidio is an open-source user management solution. In versions 5.0.0 through 5.0.6, the delete, activate, and deactivat...
CVE-2026-32755MEDIUM5.7Admidio is an open-source user management solution. In versions 5.0.6 and below, the save_membership action in modules/p...
CVE-2026-32721MEDIUM4.8LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerabil...
CVE-2026-30874HIGH7.8OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in...
CVE-2026-29107MEDIUM5.3SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29106MEDIUM6.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29105MEDIUM6.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29104LOW2.7SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29103HIGH7.2SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Rem...
CVE-2026-29102HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29101HIGH7.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29100MEDIUM6.1SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. SuiteCRM 7.15....
CVE-2026-29099HIGH8.8SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29098MEDIUM4.9SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-29097HIGH7.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions prior...
CVE-2026-29096MEDIUM6.5SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi...
CVE-2026-22732CRITICAL9.1When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now