2026 CVE Vulnerabilities

67,418 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-77610MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77609MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77608MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77607MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77606MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77339MEDIUM5.1Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listen...
CVE-2026-77301HIGH7.5adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEnt...
CVE-2026-77240CRITICAL9.9WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security...
CVE-2026-77239HIGH8.1WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation write routes...
CVE-2026-73863HIGH7NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT v5 nmq_subinfo_decode() function in nng/src/sp/pro...
CVE-2026-63406MEDIUM5.9AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemet...
CVE-2026-63405MEDIUM5.9AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the Pusher-...
CVE-2026-63349HIGH7AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In ...
CVE-2026-62943HIGH8.7btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_fil...
CVE-2026-61833HIGH8.1zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior ...
CVE-2026-61795MEDIUM6.8Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnU...
CVE-2026-61794MEDIUM6.8Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update valida...
CVE-2026-61672HIGH7.1Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in p...
CVE-2026-61633LOW2NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function nni_mqtt_msg_decode_unsubscribe() in nng/src/supp...
CVE-2026-61548HIGH8.1Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseS...
CVE-2026-58197HIGH8.8ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to Too...
CVE-2026-55556HIGH8.2Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_aut...
CVE-2026-46655HIGH7.8virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits...
CVE-2026-44639LOW3.7NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqtt_codec.c ...
CVE-2026-93737MEDIUM6.5Azkaban through 4.0.0 omits project permission checks in the ScheduleServlet fetchSchedule action, allowing authenticate...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now