2026 CVE Vulnerabilities

70,490 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-27832HIGH8.8Group-Office is an enterprise customer relationship management and groupware tool. Versions prior to 26.0.8, 25.0.87, an...
CVE-2026-27824MEDIUM5.3calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9....
CVE-2026-27810MEDIUM6.4calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9....
CVE-2026-27793MEDIUM6.5Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.1.0, the `G...
CVE-2026-27792MEDIUM5.4Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulner...
CVE-2026-27734MEDIUM6.5Beszel is a server monitoring platform. Prior to version 0.18.2, the hub's authenticated API endpoints GET /api/beszel/c...
CVE-2026-27707CRITICAL9.8Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and ...
CVE-2026-27583——Rejected reason: Further research determined the situation described is not a vulnerability.
CVE-2026-27582——Rejected reason: Further research determined the situation described is not a vulnerability.
CVE-2026-27581——Rejected reason: Further research determined the situation described is not a vulnerability.
CVE-2026-27580——Rejected reason: Further research determined the situation described is not a vulnerability.
CVE-2026-27573——Rejected reason: Further research determined the situation described is not a vulnerability.
CVE-2026-27501——Rejected reason: Further research determined the situation described is not a vulnerability.
CVE-2026-27500——Rejected reason: Further research determined the situation described is not a vulnerability.
CVE-2026-27201——Rejected reason: Further research determined the situation described is not a vulnerability.
CVE-2026-27200——Rejected reason: Further research determined the situation described is not a vulnerability.
CVE-2026-26997MEDIUM5.4ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, a normal authenticated user can stor...
CVE-2026-22717LOW2.7Out-of-bound read vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administra...
CVE-2026-2880CRITICAL9.1A vulnerability in @fastify/middie versions < 9.2.0 can result in authentication/authorization bypass when using path-sc...
CVE-2026-27758MEDIUM6.5SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a cross-site request forgery vulnerability in its man...
CVE-2026-27757HIGH7.2SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain an authentication vulnerability that allows authentic...
CVE-2026-27756MEDIUM6.1SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a reflected cross-site scripting vulnerability in the...
CVE-2026-27755CRITICAL9.8SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 contain a weak session identifier generation vulnerability th...
CVE-2026-27754MEDIUM6.9SODOLA SL902-SWTGW124AS firmware versions through 200.1.20 use the cryptographically broken MD5 hash function for sessio...
CVE-2026-22716MEDIUM5Out-of-bound write vulnerability in VMware Workstation 25H1 and below on any platform allows an actor with non-administr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now