2026 CVE Vulnerabilities

69,858 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3668LOW3.1A weakness has been identified in Freedom Factory dGEN1 up to 20260221. This affects the function AndroidEthereum of the...
CVE-2026-3667MEDIUM5.3A security flaw has been discovered in Freedom Factory dGEN1 up to 20260221. The impacted element is the function FakeAp...
CVE-2026-3665MEDIUM5.5A vulnerability was identified in xlnt-community xlnt up to 1.6.1. The affected element is the function xlnt::detail::xl...
CVE-2026-30838MEDIUM6.1league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by i...
CVE-2026-30834HIGH7.5PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Prior to version 0.7.7, ...
CVE-2026-30832CRITICAL9.1Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authentic...
CVE-2026-29787MEDIUM5.3mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.21.0, the /api/health/d...
CVE-2026-29786MEDIUM6.3node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that p...
CVE-2026-29784HIGH8.8Ghost is a Node.js content management system. From version 5.101.6 to 6.19.2, incomplete CSRF protections around /sessio...
CVE-2026-29781MEDIUM6.5Sliver is a command and control framework that uses a custom Wireguard netstack. In versions from 1.7.3 and prior, a vul...
CVE-2026-29780MEDIUM5.5eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well...
CVE-2026-29779HIGH7.5UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers. Prior to commit 377...
CVE-2026-29778MEDIUM6.5pyLoad is a free and open-source download manager written in Python. From version 0.5.0b3.dev13 to 0.5.0b3.dev96, the ed...
CVE-2026-29771MEDIUM6.5Netmaker makes networks with WireGuard. Prior to version 1.2.0, the /api/server/shutdown endpoint allows termination of ...
CVE-2026-29194HIGH8.1Netmaker makes networks with WireGuard. Prior to version 1.5.0, the Authorize middleware in Netmaker incorrectly validat...
CVE-2026-29190MEDIUM5.3Karapace is an open-source implementation of Kafka REST and Schema Registry. Prior to version 6.0.0, there is a Path Tra...
CVE-2026-29076MEDIUM5.9cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib u...
CVE-2026-28678——Rejected reason: Further research determined the issue is not a vulnerability.
CVE-2026-3664MEDIUM5.5A vulnerability was determined in xlnt-community xlnt up to 1.6.1. Impacted is the function xlnt::detail::compound_docum...
CVE-2026-3663HIGH7.1A vulnerability was found in xlnt-community xlnt up to 1.6.1. This issue affects the function xlnt::detail::compound_doc...
CVE-2026-29193HIGH8.2ZITADEL is an open source identity management platform. From version 4.0.0 to 4.12.0, a vulnerability in Zitadel's login...
CVE-2026-29192HIGH7.7ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login...
CVE-2026-29191CRITICAL9.3ZITADEL is an open source identity management platform. From version 4.0.0 to 4.11.1, a vulnerability in Zitadel's login...
CVE-2026-29186CRITICAL9.8Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass v...
CVE-2026-29185LOW2.7Backstage is an open framework for building developer portals. Prior to version 1.20.1, a vulnerability in the SCM URL p...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now