2026 CVE Vulnerabilities

67,723 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32596HIGH7.5Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.2, Glances web server runs without authent...
CVE-2026-32268HIGH8.7The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the...
CVE-2026-4366MEDIUM5.8A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirect...
CVE-2026-33189——Rejected reason: Further research determined the issue originates from a different product.
CVE-2026-33188——Rejected reason: Further research determined the issue originates from a different product.
CVE-2026-33187——Rejected reason: Further research determined the issue originates from a different product.
CVE-2026-33058MEDIUM6.5Kanboard is project management software focused on Kanban methodology. Versions prior to 1.2.51 have an authenticated SQ...
CVE-2026-32266LOW2.4The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on ...
CVE-2026-32265MEDIUM6.9The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, una...
CVE-2026-32256HIGH7.5music-metadata is a metadata parser for audio and video media files. Prior to version 11.12.3, music-metadata's ASF pars...
CVE-2026-32254HIGH7.1Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not...
CVE-2026-31938MEDIUM6.1jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of the `options` argument of the...
CVE-2026-31898MEDIUM6.5jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.2.1, user control of arguments of the `createAnnot...
CVE-2026-31891MEDIUM6.5Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API acc...
CVE-2026-31865MEDIUM5.3Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server commun...
CVE-2026-30922HIGH7.5pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service ...
CVE-2026-30884CRITICAL9.6mdjnelson/moodle-mod_customcert is a Moodle plugin for creating dynamically generated certificates with complete customi...
CVE-2026-2575MEDIUM5.3A flaw was found in Keycloak. An unauthenticated remote attacker can trigger an application level Denial of Service (DoS...
CVE-2026-29112HIGH7.5DiceBear is an avatar library for designers and developers. Prior to version 9.4.0, the `ensureSize()` function in `@dic...
CVE-2026-1926MEDIUM5.3The Subscriptions for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi...
CVE-2026-1780MEDIUM6.1The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL path in all v...
CVE-2026-4356LOW2.4A flaw has been found in itsourcecode University Management System 1.0. Affected is an unknown function of the file /add...
CVE-2026-4268MEDIUM6.4The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpgm...
CVE-2026-2603HIGH8.1A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an ...
CVE-2026-2092HIGH7.7A flaw was found in Keycloak. Keycloak's Security Assertion Markup Language (SAML) broker endpoint does not properly val...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now