2026 CVE Vulnerabilities

69,937 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3589HIGH7.5The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allo...
CVE-2026-23925HIGH8.1An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configur...
CVE-2026-2830MEDIUM6.1The WP All Import – Drag & Drop Import for CSV, XML, Excel & Google Sheets plugin for WordPress is vulnerable to Reflect...
CVE-2026-2331CRITICAL9.8An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileac...
CVE-2026-2330CRITICAL9.4An attacker may access restricted filesystem areas on the device via the CROWN REST interface due to incomplete whitelis...
CVE-2026-29183MEDIUM6.1SiYuan is a personal knowledge management system. Prior to version 3.5.9, an unauthenticated reflected XSS vulnerability...
CVE-2026-29074HIGH7.5SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version ...
CVE-2026-29073HIGH8.8SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directl...
CVE-2026-29062HIGH7.5jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Pr...
CVE-2026-29059HIGH7.5Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to vers...
CVE-2026-29068HIGH7.5PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack b...
CVE-2026-29065CRITICAL9.1changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerabili...
CVE-2026-29058CRITICAL9.8AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS ...
CVE-2026-29049MEDIUM4.3melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cach...
CVE-2026-29048MEDIUM6.1HumHub is an Open Source Enterprise Social Network. In version 1.18.0, a cross-site scripting vulnerability was identifi...
CVE-2026-29042CRITICAL9.8Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell ...
CVE-2026-29039HIGH7.5changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io...
CVE-2026-29038MEDIUM6.1changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, there is a reflected c...
CVE-2026-28804MEDIUM5.3pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability...
CVE-2026-28802CRITICAL9.8Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, p...
CVE-2026-28801HIGH7.8Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, any ahk code cont...
CVE-2026-28800HIGH8Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Disco...
CVE-2026-28799HIGH7.5PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-f...
CVE-2026-28795CRITICAL9.8OpenChatBI is an intelligent chat-based BI tool powered by large language models, designed to help users query, analyze,...
CVE-2026-28438CRITICAL9.8CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now