2026 CVE Vulnerabilities

67,740 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54506HIGH7.6Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5...
CVE-2026-54343HIGH8.7Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version ...
CVE-2026-53557HIGH7.7SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated use...
CVE-2026-53556MEDIUM6SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat...
CVE-2026-53555MEDIUM5.1SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated upl...
CVE-2026-53554HIGH7.3SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat...
CVE-2026-53534HIGH7.5JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef'...
CVE-2026-50291MEDIUM5.5OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a...
CVE-2026-50158HIGH7.7yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool ...
CVE-2026-16750MEDIUM5.3The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of da...
CVE-2026-16582MEDIUM5.3The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modificatio...
CVE-2026-14311MEDIUM5.4The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and ...
CVE-2026-11432——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-93395MEDIUM5.3A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when proc...
CVE-2026-93394LOW3.7A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and...
CVE-2026-93393HIGH8.1A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platf...
CVE-2026-93387MEDIUM4.3Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-orig...
CVE-2026-93386MEDIUM5.4UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging soci...
CVE-2026-93385MEDIUM6.5Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive informat...
CVE-2026-93384LOW3.7Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker l...
CVE-2026-93383MEDIUM4.3Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin d...
CVE-2026-93382HIGH8.8Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-93381HIGH8.8Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging soc...
CVE-2026-93380LOW3.1Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the r...
CVE-2026-93379MEDIUM4.3Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolatio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now