2026 CVE Vulnerabilities

69,027 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32334MEDIUM5.3Missing Authorization vulnerability in raratheme JobScout jobscout allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-32332MEDIUM5.3Missing Authorization vulnerability in Ays Pro Easy Form easy-form allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-32331MEDIUM5.4Missing Authorization vulnerability in Israpil Textmetrics webtexttool allows Exploiting Incorrectly Configured Access C...
CVE-2026-32330MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in 10Web Photo Gallery by 10Web photo-gallery allows Cross Site Request ...
CVE-2026-32329MEDIUM5.3Missing Authorization vulnerability in Ays Pro Advanced Related Posts advanced-related-posts allows Exploiting Incorrect...
CVE-2026-32328MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in shufflehound Lemmony lemmony allows Cross Site Request Forgery.This i...
CVE-2026-32322MEDIUM5.3soroban-sdk is a Rust SDK for Soroban contracts. Prior to 22.0.11, 23.5.3, and 25.3.0, The Fr (scalar field) types for B...
CVE-2026-32320HIGH7.5Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a PathSwitchReque...
CVE-2026-32319HIGH7.5Ella Core is a 5G core designed for private networks. Prior to 1.5.1, Ella Core panics when processing a malformed integ...
CVE-2026-32308HIGH7.6OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the Markdown viewer component ren...
CVE-2026-32306CRITICAL9.9OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the telemetry aggregation API acc...
CVE-2026-32304CRITICAL9.8Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the creat...
CVE-2026-32302HIGH8.1OpenClaw is a personal AI assistant. Prior to 2026.3.11, browser-originated WebSocket connections could bypass origin va...
CVE-2026-32301CRITICAL9.3Centrifugo is an open-source scalable real-time messaging server. Prior to 6.7.0, Centrifugo is vulnerable to Server-Sid...
CVE-2026-31949MEDIUM6.5LibreChat is a ChatGPT clone with additional features. Prior to 0.8.3-rc1, a Denial of Service (DoS) vulnerability exist...
CVE-2026-31944HIGH7.6LibreChat is a ChatGPT clone with additional features. From 0.8.2 to 0.8.2-rc3, The MCP (Model Context Protocol) OAuth c...
CVE-2026-31922HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ays Pro Fox LMS fo...
CVE-2026-31919MEDIUM4.3Missing Authorization vulnerability in Josh Kohlbach Advanced Coupons for WooCommerce Coupons advanced-coupons-for-wooco...
CVE-2026-31918MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in immonex immonex Ki...
CVE-2026-31917HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp ...
CVE-2026-31916MEDIUM5.3Missing Authorization vulnerability in Iulia Cazan Latest Post Shortcode latest-post-shortcode allows Exploiting Incorre...
CVE-2026-31915MEDIUM5.3Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-31899HIGH7.5CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of se...
CVE-2026-31897CRITICAL9.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in free...
CVE-2026-31886HIGH7.6Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now