2026 CVE Vulnerabilities

68,670 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3849CRITICAL9.8Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH (E...
CVE-2026-3549CRITICAL9.8Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buf...
CVE-2026-3547HIGH7.5Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds re...
CVE-2026-3230LOW2.7Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a c...
CVE-2026-3229MEDIUM5.5An integer overflow vulnerability existed in the static function wolfssl_add_to_chain, that caused heap corruption when ...
CVE-2026-33346HIGH8.7OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-33321HIGH7.6OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-33305MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-33304MEDIUM6.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-33303MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior ...
CVE-2026-33302HIGH8.1OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-33301HIGH8.1OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-33299MEDIUM5.4OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-32749CRITICAL9.1SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/i...
CVE-2026-32747MEDIUM4.9SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the globalCopyFiles API eads source file...
CVE-2026-32622HIGH8.8SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a S...
CVE-2026-32191CRITICAL9.8Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allo...
CVE-2026-32169CRITICAL9.8Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a net...
CVE-2026-30924CRITICAL9.6qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that r...
CVE-2026-30836CRITICAL10Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 ...
CVE-2026-27953CRITICAL9.8ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the...
CVE-2026-27740MEDIUM6.1Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cros...
CVE-2026-27570MEDIUM6.1Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox...
CVE-2026-27491MEDIUM4.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coe...
CVE-2026-27454MEDIUM5.3Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now