2026 CVE Vulnerabilities

67,521 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32737CRITICAL10Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for function...
CVE-2026-32736MEDIUM4.3The Hytale Modding Wiki is a free service for Hytale mods to host their documentation & wikis. An Insecure Direct Object...
CVE-2026-32735LOW2.3openapi-to-java-records-mustache-templates allows users to generate Java Records from OpenAPI specifications. Starting i...
CVE-2026-32731CRITICAL9.9ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`, ...
CVE-2026-32730HIGH8.1ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication m...
CVE-2026-4407LOW2.1Out-of-bounds array write in Xpdf 4.06 and earlier, due to incorrect validation of the "N" field in ICCBased color space...
CVE-2026-33163MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-33042MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32944HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32943LOW3.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32886HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32878HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32770HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32742MEDIUM4.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32728HIGH7.6Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32723MEDIUM4.7SandboxJS is a JavaScript sandboxing library. Prior to 0.8.35, SandboxJS timers have an execution-quota bypass. A global...
CVE-2026-32722MEDIUM6.1Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray rendered the command line of the tracked process ...
CVE-2026-32703MEDIUM5.4OpenProject is an open-source, web-based project management software. In versions prior to 16.6.9, 17.0.6, 17.1.3, and 1...
CVE-2026-32698HIGH7.2OpenProject is an open-source, web-based project management software. Versions prior to 16.6.9, 17.0.6, 17.1.3, and 17.2...
CVE-2026-32700MEDIUM5.3Devise is an authentication solution for Rails based on Warden. Prior to version 5.0.3, a race condition in Devise's Con...
CVE-2026-32638LOW2.7StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.4, the REST API `get...
CVE-2026-32636HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-17 and 6.9...
CVE-2026-32321HIGH8.8ClipBucket v5 is an open source video sharing platform. An authenticated time-based blind SQL injection vulnerability ex...
CVE-2026-31973HIGH7.5SAMtools is a program for reading, manipulating and writing bioinformatics file formats. Starting in version 1.17, in th...
CVE-2026-31972CRITICAL9.8SAMtools is a program for reading, manipulating and writing bioinformatics file formats. The `mpileup` command outputs D...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now