2026 CVE Vulnerabilities

69,139 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32112MEDIUM4.7ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form renders user-controlled parameters ...
CVE-2026-32111MEDIUM5.3ha-mcp is a Home Assistant MCP Server. Prior to 7.0.0, the ha-mcp OAuth consent form (beta feature) accepts a user-suppl...
CVE-2026-32110HIGH8.3SiYuan is a personal knowledge management system. Prior to 3.6.0, the /api/network/forwardProxy endpoint allows authenti...
CVE-2026-32109MEDIUM4.4Copyparty is a portable file server. Prior to 1.20.12, if an attacker has been given both read- and write-permissions to...
CVE-2026-32108MEDIUM6.5Copyparty is a portable file server. Prior to 1.20.12, there was a missing permission-check in the shares feature (the s...
CVE-2026-32106HIGH7.2StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the REST API crea...
CVE-2026-32104MEDIUM5.4StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the updateUserNot...
CVE-2026-32103HIGH7.2StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the POST /studioc...
CVE-2026-32102MEDIUM6.5OliveTin gives access to predefined shell commands from a web interface. In 3000.10.2 and earlier, OliveTin’s live Event...
CVE-2026-32101MEDIUM6.3StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.3.1, the S3 storage ma...
CVE-2026-2640MEDIUM5.5During an internal security assessment, a potential vulnerability was discovered in Lenovo PC Manager that could allow a...
CVE-2026-2368HIGH7.1An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user ca...
CVE-2026-1717MEDIUM6.8An input validation vulnerability was reported in the LenovoProductivitySystemAddin used in Lenovo Vantage and Lenovo Ba...
CVE-2026-1716HIGH7.1An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiyin...
CVE-2026-1715HIGH7.1An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiyin...
CVE-2026-1653MEDIUM5.5A potential divide by zero vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could ...
CVE-2026-1652MEDIUM6.1A potential buffer overflow vulnerability was reported in the Lenovo Virtual Bus driver used in Smart Connect that could...
CVE-2026-1068MEDIUM5.3An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user ca...
CVE-2026-0940HIGH8.4A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local pr...
CVE-2026-0520LOW2.8A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could all...
CVE-2026-3954MEDIUM6.5A weakness has been identified in OpenBMB XAgent 1.0.0. Affected by this vulnerability is the function workspace of the ...
CVE-2026-3951MEDIUM4.3A security flaw has been discovered in LockerProject Locker 0.0.0/0.0.1/0.1.0. Affected is the function authIsAwesome of...
CVE-2026-3950LOW3.3A vulnerability was identified in strukturag libheif up to 1.21.2. This impacts the function Track::load of the file lib...
CVE-2026-32234MEDIUM4.7Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32098HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now