2026 CVE Vulnerabilities

70,478 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28352MEDIUM6.5Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In vers...
CVE-2026-28351MEDIUM5.3pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.4, an attacker who uses this vulnerability...
CVE-2026-28338MEDIUM6.1PMD is an extensible multilanguage static code analyzer. Prior to version 7.22.0, PMD's `vbhtml` and `yahtml` report for...
CVE-2026-28288MEDIUM5.3Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-exi...
CVE-2026-28272MEDIUM4.8Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway...
CVE-2026-28271MEDIUM6.5Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functional...
CVE-2026-28270HIGH7.2Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration allows upl...
CVE-2026-28268CRITICAL9.8Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerabil...
CVE-2026-3255MEDIUM6.5HTTP::Session2 versions before 1.12 for Perl for Perl may generate weak session ids using the rand() function. The HTTP...
CVE-2026-28354MEDIUM6.5ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulne...
CVE-2026-28231CRITICAL9.1pillow_heif is a Python library for working with HEIF images and plugin for Pillow. Prior to version 1.3.0, an integer o...
CVE-2026-27947HIGH8.8Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.9, 25.0.87, an...
CVE-2026-27836HIGH7.5phpMyFAQ is an open source FAQ web application. Prior to version 4.0.18, the WebAuthn prepare endpoint (`/api/webauthn/p...
CVE-2026-27832HIGH8.8Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.8, 25.0.87, an...
CVE-2026-27824MEDIUM5.3calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9....
CVE-2026-27810MEDIUM6.4calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9....
CVE-2026-27793MEDIUM6.5Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.1.0, the `G...
CVE-2026-27792MEDIUM5.4Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulner...
CVE-2026-27734MEDIUM6.5Beszel is a server monitoring platform. Prior to version 0.18.2, the hub's authenticated API endpoints GET /api/beszel/c...
CVE-2026-27707CRITICAL9.8Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and ...
CVE-2026-27583——Rejected reason: Further research determined the situation described is not a vulnerability.
CVE-2026-27582——Rejected reason: Further research determined the situation described is not a vulnerability.
CVE-2026-27581——Rejected reason: Further research determined the situation described is not a vulnerability.
CVE-2026-27580——Rejected reason: Further research determined the situation described is not a vulnerability.
CVE-2026-27573——Rejected reason: Further research determined the situation described is not a vulnerability.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now