2026 CVE Vulnerabilities

69,030 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-31899HIGH7.5CairoSVG is an SVG converter based on Cairo, a 2D graphics library. Prior to Kozea/CairoSVG has exponential denial of se...
CVE-2026-31897CRITICAL9.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in free...
CVE-2026-31886HIGH7.6Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the...
CVE-2026-31885CRITICAL9.4FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, there is an out-of-bounds read in MS-A...
CVE-2026-31884HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, division by zero in MS-ADPCM and IMA-A...
CVE-2026-31883CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a size_t underflow in the IMA-ADPCM an...
CVE-2026-31882HIGH7.5Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, when Dagu is configured with HTTP Basic au...
CVE-2026-31864MEDIUM6.8JumpServer is an open source bastion host and an operation and maintenance security audit system. a Server-Side Template...
CVE-2026-31814HIGH7.5Yamux is a stream multiplexer over reliable, ordered connections such as TCP/IP. From 0.13.0 to before 0.13.9, a special...
CVE-2026-31806CRITICAL9.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function proce...
CVE-2026-31798MEDIUM5JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts,...
CVE-2026-30961MEDIUM4.3Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, the chunke...
CVE-2026-30955MEDIUM6.5Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An API end...
CVE-2026-30943MEDIUM4.1Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insuffi...
CVE-2026-30915MEDIUM4.3SFTPGo is an open source, event-driven file transfer solution. SFTPGo versions before v2.7.1 contain an input validation...
CVE-2026-30914HIGH8.1SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization d...
CVE-2026-30853HIGH8.2calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a p...
CVE-2026-2890HIGH7.5The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and includi...
CVE-2026-2888MEDIUM5.3The Formidable Forms plugin for WordPress is vulnerable to an authorization bypass through user-controlled key in all ve...
CVE-2026-2879MEDIUM5.4The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including...
CVE-2026-2859MEDIUM4.3Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows...
CVE-2026-2673MEDIUM6.5Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key ex...
CVE-2026-2257MEDIUM6.4The GetGenie plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including...
CVE-2026-29776LOW3.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, Integer Underflow in update_read_cache...
CVE-2026-29775HIGH8.2FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap out-of-bounds read/...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now