2026 CVE Vulnerabilities

68,816 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32706HIGH8.1PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized vari...
CVE-2026-32705MEDIUM6.8PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the BST telemetry probe writes a string term...
CVE-2026-32704MEDIUM6.5SiYuan is a personal knowledge management system. Prior to 3.6.1, POST /api/template/renderSprig lacks model.CheckAdminR...
CVE-2026-32702MEDIUM5.3Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c...
CVE-2026-32640CRITICAL9.8SimpleEval is a library for adding evaluatable expressions into python projects. Prior to 1.0.5, objects (including modu...
CVE-2026-32635CRITICAL9Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-32630MEDIUM5.3file-type detects the file type of a file, stream, or data. From 20.0.0 to 21.3.1, a crafted ZIP file can trigger excess...
CVE-2026-32628HIGH8.8AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-32627HIGH8.1cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.2, when a cpp-httplib cl...
CVE-2026-32626CRITICAL9.6AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-32621CRITICAL9.9Apollo Federation is an architecture for declaratively composing APIs into a unified graph. Prior to 2.9.6, 2.10.5, 2.11...
CVE-2026-32617HIGH7.5AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-32616HIGH8.2Pigeon is a message board/notepad/social system/blog. Prior to 1.0.201, the application uses $_SERVER['HTTP_HOST'] witho...
CVE-2026-32614HIGH7.5Go ShangMi (Commercial Cryptography) Library (GMSM) is a cryptographic library that covers the Chinese commercial crypto...
CVE-2026-32600HIGH8.2xml-security is a library that implements XML signatures and encryption. Prior to versions 2.3.1 and 1.13.9, XML nodes e...
CVE-2026-32594HIGH7.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.40 ...
CVE-2026-32314HIGH7.5Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. Prior to 0.13.10, the Rust implementati...
CVE-2026-32313HIGH8.2xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypt...
CVE-2026-31386HIGH8.6OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An a...
CVE-2026-2923HIGH7.8GStreamer DVB Subtitles Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attack...
CVE-2026-2922HIGH7.8GStreamer RealMedia Demuxer Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote at...
CVE-2026-2921HIGH7.8GStreamer RIFF Palette Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers ...
CVE-2026-2920HIGH7.8GStreamer ASF Demuxer Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2026-2578MEDIUM4.3Mattermost versions 11.3.x <= 11.3.0 fail to preserve the redacted state of burn-on-read posts during deletion which all...
CVE-2026-2493HIGH7.5IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attacke...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now