2026 CVE Vulnerabilities

68,809 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3020HIGH8.6Identity based authorization bypass vulnerability (IDOR) that allows an attacker to modify the data of a legitimate user...
CVE-2026-32778MEDIUM5.5libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memo...
CVE-2026-32777MEDIUM5.5libexpat before 2.7.5 allows an infinite loop while parsing DTD content.
CVE-2026-32776MEDIUM5.5libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.
CVE-2026-32775HIGH7.8libexif through 0.6.25 has a flaw in decoding MakerNotes. If the exif_mnote_data_get_value function gets passed in a 0 s...
CVE-2026-32774MEDIUM5.4Vulnogram 1.0.0 contains a stored cross-site scripting vulnerability in comment hypertext handling that allows attackers...
CVE-2026-32772MEDIUM4.7telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON ...
CVE-2026-32732NONE0Lean 4 VS Code Extension is a Visual Studio Code extension for the Lean 4 proof assistant. Projects that use @leanprover...
CVE-2026-32729HIGH8.8Runtipi is a personal homeserver orchestrator. Prior to 4.8.1, The Runtipi /api/auth/verify-totp endpoint does not enfor...
CVE-2026-32724MEDIUM5.3PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc1, a heap-use-after-free is detected in the Mav...
CVE-2026-32720HIGH7.1The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, met...
CVE-2026-32719MEDIUM6.4AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-32717LOW2.7AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-32715LOW3.8AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-32713MEDIUM6.5PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, A logic error in the PX4 Autopilot MAVLink F...
CVE-2026-32709MEDIUM6.8PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, An unauthenticated path traversal vulnerabil...
CVE-2026-32708HIGH8PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack ...
CVE-2026-32707MEDIUM6.1PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, tattu_can contains an unbounded memcpy in it...
CVE-2026-32706HIGH8.1PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized vari...
CVE-2026-32705MEDIUM6.8PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the BST telemetry probe writes a string term...
CVE-2026-32704MEDIUM6.5SiYuan is a personal knowledge management system. Prior to 3.6.1, POST /api/template/renderSprig lacks model.CheckAdminR...
CVE-2026-32702MEDIUM5.3Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c...
CVE-2026-32640CRITICAL9.8SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modu...
CVE-2026-32635CRITICAL9Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-32630MEDIUM5.3file-type detects the file type of a file, stream, or data. From 20.0.0 to 21.3.1, a crafted ZIP file can trigger excess...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now