2026 CVE Vulnerabilities

69,036 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32259MEDIUM6.7ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9...
CVE-2026-32251MEDIUM6.5Tolgee is an open-source localization platform. Prior to 3.166.3, the XML parsers used for importing Android XML resourc...
CVE-2026-32249MEDIUM5.5Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encoun...
CVE-2026-32248CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32240MEDIUM6.5Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: ...
CVE-2026-32239MEDIUM6.5Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length valu...
CVE-2026-1525CRITICAL9.8Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Co...
CVE-2026-3497HIGH7.5Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI...
CVE-2026-32247HIGH8.1Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2...
CVE-2026-32246HIGH7.1Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users wit...
CVE-2026-32245MEDIUM6.5Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the...
CVE-2026-32242HIGH7.4Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32237MEDIUM6.5Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to ex...
CVE-2026-32236HIGH7.5Backstage is an open framework for building developer portals. Prior to 0.27.1, a Server-Side Request Forgery (SSRF) vul...
CVE-2026-32235MEDIUM4.7Backstage is an open framework for building developer portals. Prior to 0.27.1, the experimental OIDC provider in @backs...
CVE-2026-32232CRITICAL9.8ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Valid...
CVE-2026-32231HIGH8.2ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields...
CVE-2026-32230MEDIUM5.3Uptime Kuma is an open source, self-hosted monitoring tool. From 2.0.0 to 2.1.3 , the GET /api/badge/:id/ping/:duration?...
CVE-2026-32142MEDIUM5.3Shopware is an open commerce platform. /api/_info/config route exposes information about licenses. This vulnerability is...
CVE-2026-32138HIGH8.2NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. P...
CVE-2026-2376MEDIUM5.4A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal ...
CVE-2026-26793CRITICAL9.8GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. Thi...
CVE-2026-3841HIGH8.8A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5...
CVE-2026-32141HIGH7.5flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve...
CVE-2026-32140HIGH8.8Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now