2026 CVE Vulnerabilities

69,544 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-31832MEDIUM5.4Umbraco is an ASP.NET CMS. From 14.0.0 to before 16.5.1 and 17.2.2, A broken object-level authorization vulnerability ex...
CVE-2026-31830HIGH7.5sigstore-ruby is a pure Ruby implementation of the sigstore verify command from the sigstore/cosign project. Prior to 0....
CVE-2026-31829HIGH8.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise expose...
CVE-2026-31828HIGH8.8Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.2-a...
CVE-2026-31827HIGH7.1Alienbin is an anonymous code and text sharing web service. In 1.0.0 and earlier, the /save endpoint in server.js drops ...
CVE-2026-31826MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.8.0, an attacker who uses this vulnerability can cra...
CVE-2026-31825MEDIUM5.3Sylius is an Open Source eCommerce Framework on Symfony. Sylius API filters ProductPriceOrderFilter and TranslationOrder...
CVE-2026-31824MEDIUM5.9Sylius is an Open Source eCommerce Framework on Symfony. A Time-of-Check To Time-of-Use (TOCTOU) race condition was disc...
CVE-2026-31823MEDIUM4.8Sylius is an Open Source eCommerce Framework on Symfony. An authenticated stored cross-site scripting (XSS) vulnerabilit...
CVE-2026-31822MEDIUM6.1Sylius is an Open Source eCommerce Framework on Symfony. A cross-site scripting (XSS) vulnerability exists in the shop c...
CVE-2026-31821MEDIUM5.3Sylius is an Open Source eCommerce Framework on Symfony. The POST /api/v2/shop/orders/{tokenValue}/items endpoint does n...
CVE-2026-31820MEDIUM6.5Sylius is an Open Source eCommerce Framework on Symfony. An authenticated Insecure Direct Object Reference (IDOR) vulner...
CVE-2026-31819MEDIUM6.1Sylius is an Open Source eCommerce Framework on Symfony. CurrencySwitchController::switchAction(), ImpersonateUserContro...
CVE-2026-31817HIGH8.5OliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature i...
CVE-2026-31815MEDIUM5.3Unicorn adds modern reactive component functionality to your Django templates. Prior to 0.67.0, component state manipula...
CVE-2026-31812MEDIUM5.3Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Prior to 0.11.14, a remote, u...
CVE-2026-28807HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in gleam-wisp wisp allows a...
CVE-2026-28806HIGH8.8Improper Authorization vulnerability in nerves-hub nerves_hub_web allows cross-organization device control via device bu...
CVE-2026-27278HIGH7.8Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerabil...
CVE-2026-27221MEDIUM5.5Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by an Improper Certificate Val...
CVE-2026-27220HIGH7.8Acrobat Reader versions 24.001.30307, 24.001.30308, 25.001.21265 and earlier are affected by a Use After Free vulnerabil...
CVE-2026-31809MEDIUM6.1SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) checks href attr...
CVE-2026-31808MEDIUM5.3file-type detects the file type of a file, stream, or data. Prior to 21.3.1, a denial of service vulnerability exists in...
CVE-2026-31807MEDIUM6.1SiYuan is a personal knowledge management system. Prior to 3.5.10, SiYuan's SVG sanitizer (SanitizeSVG) blocks dangerous...
CVE-2026-31801HIGH7.7zot is ancontainer image/artifact registry based on the Open Container Initiative Distribution Specification. From 1.3.0...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now