2026 CVE Vulnerabilities

69,853 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28433MEDIUM4.3Misskey is an open source, federated social media platform. All Misskey servers running versions 10.93.0 and later, but ...
CVE-2026-28432HIGH7.5Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerabilit...
CVE-2026-28431HIGH7.5Misskey is an open source, federated social media platform. All Misskey servers running versions 8.45.0 and later, but p...
CVE-2026-26982HIGH8.8Ghostty is a cross-platform terminal emulator. Ghostty allows control characters such as 0x03 (Ctrl+C) in pasted and dro...
CVE-2026-1776MEDIUM6.5Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS ...
CVE-2026-3288HIGH8.8A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotati...
CVE-2026-31816CRITICAL9.1Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.4 and earlier, the Bud...
CVE-2026-30240HIGH8.1Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.31.5 and earlier, a path ...
CVE-2026-25960CRITICAL9.8vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add...
CVE-2026-25737CRITICAL9Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.24.0 and earlier, an arbi...
CVE-2026-25045HIGH8.8Budibase is a low code platform for creating internal tools, workflows, and admin panels. This issue is a combination of...
CVE-2026-25041HIGH7.2Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the Po...
CVE-2026-0846HIGH7.5A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file rea...
CVE-2026-3638MEDIUM5.9Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a lo...
CVE-2026-30140HIGH7.5An incorrect access control vulnerability exists in Tenda W15E V02.03.01.26_cn. An unauthenticated attacker can access t...
CVE-2026-29023HIGH7.3Keygraph Shannon contains a hard-coded API key in its router configuration that, when the router component is enabled an...
CVE-2026-3588MEDIUM5.5A server-side request forgery (SSRF) vulnerability in IKEA Dirigera v2.866.4 allows an attacker to exfiltrate private ke...
CVE-2026-25866HIGH8.5MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExe...
CVE-2026-3089MEDIUM6.5Actual Sync Server allows authenticated users to upload files through POST /sync/upload-user-file. In versions prior to ...
CVE-2026-2919MEDIUM4.3Malicious scripts could display attacker-controlled web content under spoofed domains in Focus for iOS by stalling a _se...
CVE-2026-3819MEDIUM5.4A vulnerability has been found in SourceCodester Resort Reservation System 1.0. The affected element is an unknown funct...
CVE-2026-3038HIGH7.5The rtsock_msg_buffer() function serializes routing information into a buffer. As a part of this, it copies sockaddr st...
CVE-2026-2261HIGH7.5Due to a programming error, blocklistd leaks a socket descriptor for each adverse event report it receives. Once a cert...
CVE-2026-21736MEDIUM4.4Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permission to re...
CVE-2026-3818CRITICAL9.8A flaw has been found in Tiandy Easy7 CMS Windows 7.17.0. Impacted is an unknown function of the file /Easy7/apps/WebSer...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now