2026 CVE Vulnerabilities

69,502 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-31870HIGH7.5cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib cl...
CVE-2026-31868MEDIUM6.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-31867MEDIUM4.8Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (I...
CVE-2026-31866HIGH7.5flagd is a feature flag daemon with a Unix philosophy. Prior to 0.14.2, flagd exposes OFREP (/ofrep/v1/evaluate/...) and...
CVE-2026-31863MEDIUM4.4Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API ca...
CVE-2026-31862HIGH8.8Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1...
CVE-2026-31861HIGH8.8Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1...
CVE-2026-31859MEDIUM6.1Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in...
CVE-2026-31858HIGH8.8Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() ...
CVE-2026-31857HIGH8.8Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in t...
CVE-2026-31856CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection ...
CVE-2026-30226HIGH7.5Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the ...
CVE-2026-0231MEDIUM5.7An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obta...
CVE-2026-0230MEDIUM4A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator t...
CVE-2026-3429MEDIUM4.2A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to ...
CVE-2026-31854HIGH8.8Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted i...
CVE-2026-31853MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9...
CVE-2026-31852CRITICAL9.8Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulner...
CVE-2026-31840CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-31839HIGH7.5Striae is a firearms examiner's comparison companion. A high-severity integrity bypass vulnerability existed in Striae's...
CVE-2026-31813MEDIUM4.8Supabase Auth is a JWT based API for managing users and issuing JWT tokens. Prior to 2.185.0, a vulnerability has been i...
CVE-2026-30868HIGH8.1OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, multiple OPNsense MVC API endpoints perform ...
CVE-2026-30239HIGH7.1OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the wor...
CVE-2026-30236MEDIUM4.3OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when editing a project budget and...
CVE-2026-30235MEDIUM6.5OpenProject is an open-source, web-based project management software. Prior to 17.2.0, this vulnerability occurs due to ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now