2026 CVE Vulnerabilities

69,211 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-31878MEDIUM5Frappe is a full-stack web application framework. Prior to 14.100.1, 15.100.0, and 16.6.0, a malicious user could send a...
CVE-2026-31877CRITICAL9.8Frappe is a full-stack web application framework. Prior to 15.84.0 and 14.99.0, a specially crafted request made to a ce...
CVE-2026-31876MEDIUM5.4Notesnook is a note-taking app focused on user privacy & ease of use. Prior to 3.3.9, a Stored Cross-Site Scripting (XSS...
CVE-2026-31874CRITICAL9.8Taskosaur is an open source project management platform with conversational AI for task execution in-app. In 1.0.0, the ...
CVE-2026-24509MEDIUM5.5Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Access Control vulnerability. A l...
CVE-2026-31975CRITICAL9.8Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1...
CVE-2026-31875MEDIUM5.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-31872HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-31871CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-31870HIGH7.5cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib cl...
CVE-2026-31868MEDIUM6.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-31867MEDIUM4.8Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (I...
CVE-2026-31866HIGH7.5flagd is a feature flag daemon with a Unix philosophy. Prior to 0.14.2, flagd exposes OFREP (/ofrep/v1/evaluate/...) and...
CVE-2026-31863MEDIUM4.4Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API ca...
CVE-2026-31862HIGH8.8Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1...
CVE-2026-31861HIGH8.8Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1...
CVE-2026-31859MEDIUM6.1Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in...
CVE-2026-31858HIGH8.8Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() ...
CVE-2026-31857HIGH8.8Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in t...
CVE-2026-31856CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection ...
CVE-2026-30226HIGH7.5Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the ...
CVE-2026-0231MEDIUM5.7An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obta...
CVE-2026-0230MEDIUM4A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator t...
CVE-2026-3429MEDIUM4.2A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to ...
CVE-2026-31854HIGH8.8Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now