2026 CVE Vulnerabilities

70,003 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-29059HIGH7.5Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to vers...
CVE-2026-29068HIGH7.5PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack b...
CVE-2026-29065CRITICAL9.1changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, a Zip Slip vulnerabili...
CVE-2026-29058CRITICAL9.8AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS ...
CVE-2026-29049MEDIUM4.3melange allows users to build apk packages using declarative pipelines. In version 0.40.5 and prior, melange update-cach...
CVE-2026-29048MEDIUM6.1HumHub is an Open Source Enterprise Social Network. In version 1.18.0, a cross-site scripting vulnerability was identifi...
CVE-2026-29042CRITICAL9.8Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.15.20, the Nuclio Shell ...
CVE-2026-29039HIGH7.5changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io...
CVE-2026-29038MEDIUM6.1changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, there is a reflected c...
CVE-2026-28804MEDIUM5.3pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability...
CVE-2026-28802CRITICAL9.8Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, p...
CVE-2026-28801HIGH7.8Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, any ahk code cont...
CVE-2026-28800HIGH8Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Disco...
CVE-2026-28799HIGH7.5PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-f...
CVE-2026-28795CRITICAL9.8OpenChatBI is an intelligent chat-based BI tool powered by large language models, designed to help users query, analyze,...
CVE-2026-28438CRITICAL9.8CocoIndex is a data transformation framework for AI. Prior to version 0.3.34, the Doris target connector didn't verify t...
CVE-2026-2446CRITICAL9.8The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action,...
CVE-2026-1128MEDIUM4.3The WP eCommerce WordPress plugin through 3.15.1 does not have CSRF check in place when deleting coupons, which could al...
CVE-2026-29084MEDIUM4.6Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, th...
CVE-2026-29061MEDIUM5.4Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a ...
CVE-2026-29060MEDIUM5Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a ...
CVE-2026-28794CRITICAL9.8oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1....
CVE-2026-28787CRITICAL9OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authenti...
CVE-2026-28785CRITICAL9.8Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an at...
CVE-2026-28685MEDIUM6.5Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now