2026 CVE Vulnerabilities

69,057 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32100MEDIUM5.3Shopware is an open commerce platform. /api/_info/config route exposes information about active security fixes. This vul...
CVE-2026-31890MEDIUM5.5Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li...
CVE-2026-31873MEDIUM6.1Unhead is a document head and template manager. Prior to 2.1.11, The link.href check in makeTagSafe (safe.ts) uses Strin...
CVE-2026-31860MEDIUM6.1Unhead is a document head and template manager. Prior to 2.1.11, useHeadSafe() can be bypassed to inject arbitrary HTML ...
CVE-2026-28256CRITICAL9.8A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge coul...
CVE-2026-28255CRITICAL9.8A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attack...
CVE-2026-28254HIGH7.5A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticate...
CVE-2026-28253HIGH7.5A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could a...
CVE-2026-28252CRITICAL9.8A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge co...
CVE-2026-26795CRITICAL9.8GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the ...
CVE-2026-26794HIGH8.8GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This v...
CVE-2026-26792CRITICAL9.8GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade func...
CVE-2026-26791CRITICAL9.8GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in...
CVE-2026-4045LOW3.7A flaw has been found in projectsend up to r1945. This impacts an unknown function of the file includes/Classes/Auth.php...
CVE-2026-31841MEDIUM6.5Hyperterse is a tool-first MCP framework for building AI-ready backend surfaces from declarative config. Prior to v2.2.0...
CVE-2026-29066MEDIUM6.2Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI dev server configures Vite with server.fs....
CVE-2026-28793HIGH8.4Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints...
CVE-2026-28792CRITICAL9.6Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS con...
CVE-2026-28791HIGH7.4Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS devel...
CVE-2026-28356HIGH7.5multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header...
CVE-2026-27940HIGH7.8llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is ...
CVE-2026-25529HIGH8.1Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed un...
CVE-2026-24125MEDIUM6.3Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content...
CVE-2026-21887HIGH7.7OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.8.16, th...
CVE-2026-21708CRITICAL9.9A vulnerability allowing a Backup Viewer to perform remote code execution (RCE) as the postgres user.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now