2026 CVE Vulnerabilities

69,888 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-30230HIGH7.5Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1....
CVE-2026-30229HIGH7.2Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-30228MEDIUM4.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-30227MEDIUM5.3MimeKit is a C# library which may be used for the creation and parsing of messages using the Multipurpose Internet Mail ...
CVE-2026-30225MEDIUM4.3OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, an authentication c...
CVE-2026-30224MEDIUM5.4OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not r...
CVE-2026-30223HIGH8.8OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentica...
CVE-2026-29795HIGH7.5stellar-xdr is a library and CLI containing types and functionality for working with Stellar XDR. Prior to version 25.0....
CVE-2026-29791MEDIUM6.5Agentgateway is an open source data plane for agentic AI connectivity within or across any agent framework or environmen...
CVE-2026-29790MEDIUM5.3dbt-common is the shared common utilities for dbt-core and adapter implementations use. Prior to versions 1.34.2 and 1.3...
CVE-2026-29789HIGH8.8Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Pri...
CVE-2026-29788HIGH7.5TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigati...
CVE-2026-29182HIGH7.2Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-30847MEDIUM6.5Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the notificationUsers publicatio...
CVE-2026-30846HIGH7.5Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication e...
CVE-2026-30845HIGH8.2Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication ...
CVE-2026-30844HIGH8.1Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forg...
CVE-2026-30843MEDIUM6.5Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 have a critical Insecure Direct Object Ref...
CVE-2026-3653——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-29063CRITICAL9.8Immutable.js provides many Persistent Immutable data structures. Prior to versions 3.8.3, 4.3.7, and 5.1.5, Prototype Po...
CVE-2026-3419MEDIUM5.3Fastify incorrectly accepts malformed `Content-Type` headers containing trailing characters after the subtype token, in ...
CVE-2026-30833MEDIUM5.3Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.1...
CVE-2026-30831CRITICAL9.8Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.1...
CVE-2026-29178HIGH7.7Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on a...
CVE-2026-29110MEDIUM5.3Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.0, in non-debug mode Cryptomator m...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now