2026 CVE Vulnerabilities

69,141 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32234MEDIUM4.7Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32098HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32097HIGH8.8PingPong is a platform for using large language models (LLMs) for teaching and learning. Prior to 7.27.2, an authenticat...
CVE-2026-32096HIGH8.6Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vul...
CVE-2026-32095MEDIUM5.4Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.1, Plunk's image upload endpoint accepted S...
CVE-2026-32094MEDIUM6.5Shescape is a simple shell escape library for JavaScript. Prior to 2.1.10, Shescape#escape() does not escape square-brac...
CVE-2026-31979HIGH7.8Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelbla...
CVE-2026-31976CRITICAL9.8xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credenti...
CVE-2026-31974MEDIUM4.3OpenProject is an open-source, web-based project management software. Prior to 17.2.0, OpenProject SMTP test endpoint (P...
CVE-2026-31961MEDIUM5.5Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains an unb...
CVE-2026-31960MEDIUM5.3Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 has unbounded r...
CVE-2026-31959MEDIUM5.3Quill provides simple mac binary signing and notarization from any platform. Quill before version v0.7.1 contains a Serv...
CVE-2026-31958HIGH7.5Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only l...
CVE-2026-31957CRITICAL10Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 3.0.0 to before 3.1.0, if Himmelbl...
CVE-2026-31954HIGH7.3Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lac...
CVE-2026-31901MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.34 ...
CVE-2026-31900CRITICAL9.8Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action suppo...
CVE-2026-31896CRITICAL9.8WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exist...
CVE-2026-31895HIGH8.8WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, WeGIA (Web gerenciador para instituições ass...
CVE-2026-31894HIGH7.5WeGIA is a web manager for charitable institutions. In 3.6.5, The patched loadBackupDB() extracts tar.gz archives to a t...
CVE-2026-31889HIGH8.9Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration ...
CVE-2026-27703CRITICAL9.8RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ...
CVE-2026-27478CRITICAL9.1Unity Catalog is an open, multi-modal Catalog for data and AI. In 0.4.0 and earlier, a critical authentication bypass vu...
CVE-2026-24510HIGH7.8Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Privilege Management vulnerabilit...
CVE-2026-24508MEDIUM5.5Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Certificate Validation vulnerabil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now