2026 CVE Vulnerabilities

69,786 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-30969CRITICAL9.1Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The I...
CVE-2026-30968CRITICAL9.8Coral Server is open collaboration infrastructure that enables communication, coordination, trust and payments for The I...
CVE-2026-30964MEDIUM5.4web-auth/webauthn-lib is an open source set of PHP libraries and a Symfony bundle to allow developers to integrate that ...
CVE-2026-30960CRITICAL9.4rssn is a scientific computing library for Rust, combining a high-performance symbolic computation engine with numerical...
CVE-2026-30959MEDIUM5OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any au...
CVE-2026-30958HIGH8.6OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal...
CVE-2026-30957CRITICAL9.9OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, OneUptime Synthetic Monitors allo...
CVE-2026-30956CRITICAL9.9OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, a low‑privileged user can bypass ...
CVE-2026-30945HIGH7.1StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studi...
CVE-2026-30944HIGH8.8StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_ap...
CVE-2026-30942MEDIUM6.5Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to 1.7.3, an ...
CVE-2026-30941HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.14 ...
CVE-2026-30939HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.13 ...
CVE-2026-30938MEDIUM5.3Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.12 ...
CVE-2026-30934MEDIUM5.4FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is ...
CVE-2026-30933HIGH7.5FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediatio...
CVE-2026-30930CRITICAL9.8Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, The TimescaleDB export module construct...
CVE-2026-30928HIGH7.5Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint ret...
CVE-2026-30897MEDIUM6.6A stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, Fort...
CVE-2026-2742MEDIUM5.3An authentication bypass vulnerability exists in Vaadin 14.0.0 through 14.14.0, 23.0.0 through 23.6.6, 24.0.0 through 24...
CVE-2026-2741MEDIUM6.8Specially crafted ZIP archives can escape the intended extraction directory during Node.js download and extraction in Va...
CVE-2026-2724HIGH7.2The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entr...
CVE-2026-2339HIGH7.5Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Li...
CVE-2026-2273HIGH8.2CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untr...
CVE-2026-27661MEDIUM5.3A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application leaks co...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now