2026 CVE Vulnerabilities

68,634 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33301HIGH8.1OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-33299MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-32749CRITICAL9.1SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/i...
CVE-2026-32747MEDIUM4.9SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the globalCopyFiles API eads source file...
CVE-2026-32622HIGH8.8SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a S...
CVE-2026-32191CRITICAL9.8Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allo...
CVE-2026-32169CRITICAL9.8Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a net...
CVE-2026-30924CRITICAL9.6qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that r...
CVE-2026-30836CRITICAL10Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 ...
CVE-2026-27953CRITICAL9.8ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the...
CVE-2026-27740MEDIUM6.1Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cros...
CVE-2026-27570MEDIUM6.1Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox...
CVE-2026-27491MEDIUM4.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coe...
CVE-2026-27454MEDIUM5.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting...
CVE-2026-27166MEDIUM5.4Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficie...
CVE-2026-26139HIGH8.6Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net...
CVE-2026-26138CRITICAL10Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a net...
CVE-2026-26137CRITICAL9.9Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a netw...
CVE-2026-26136HIGH7.5Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut...
CVE-2026-26120HIGH7.5Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network...
CVE-2026-24299MEDIUM5.3Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...
CVE-2026-23659HIGH7.5Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disc...
CVE-2026-23658CRITICAL9.8Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a networ...
CVE-2026-3580MEDIUM4.7In wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bnez) by...
CVE-2026-3579MEDIUM5.9wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication. The...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now