2026 CVE Vulnerabilities

67,358 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33299MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-32749CRITICAL9.1SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/i...
CVE-2026-32747MEDIUM4.9SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the globalCopyFiles API eads source file...
CVE-2026-32622HIGH8.8SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a S...
CVE-2026-32191CRITICAL9.8Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allo...
CVE-2026-32169CRITICAL9.8Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a net...
CVE-2026-30924CRITICAL9.6qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that r...
CVE-2026-30836CRITICAL10Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 ...
CVE-2026-27953CRITICAL9.8ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the...
CVE-2026-27740MEDIUM6.1Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cros...
CVE-2026-27570MEDIUM6.1Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox...
CVE-2026-27491MEDIUM4.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coe...
CVE-2026-27454MEDIUM5.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting...
CVE-2026-27166MEDIUM5.4Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficie...
CVE-2026-26139HIGH8.6Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net...
CVE-2026-26138CRITICAL10Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net...
CVE-2026-26137CRITICAL9.9Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a netw...
CVE-2026-26136HIGH7.5Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut...
CVE-2026-26120HIGH7.5Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network...
CVE-2026-24299MEDIUM5.3Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...
CVE-2026-23659HIGH7.5Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disc...
CVE-2026-23658CRITICAL9.8Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a networ...
CVE-2026-3580MEDIUM4.7In wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bnez) by...
CVE-2026-3579MEDIUM5.9wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication. The...
CVE-2026-32238CRITICAL9.1OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now