2026 CVE Vulnerabilities

67,770 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54596HIGH8.1ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi...
CVE-2026-54565MEDIUM4.7rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox e...
CVE-2026-54521MEDIUM6.1FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP...
CVE-2026-54510HIGH7.1Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the...
CVE-2026-54501CRITICAL9.4Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through...
CVE-2026-54460CRITICAL9.8OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1...
CVE-2026-54355MEDIUM5.3MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML outpu...
CVE-2026-54354HIGH8.2MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter tran...
CVE-2026-54339HIGH7.7Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passe...
CVE-2026-54237CRITICAL9.3Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /instal...
CVE-2026-52483HIGH8.8The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(...
CVE-2026-50277HIGH7.5dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggag...
CVE-2026-50275HIGH7.5The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddt...
CVE-2026-50022MEDIUM5.8Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSo...
CVE-2026-49137——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-48977HIGH7.7OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() pro...
CVE-2026-45143CRITICAL9Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private ...
CVE-2026-45140CRITICAL9.8Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote a...
CVE-2026-15815HIGH8.8Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plug...
CVE-2026-11314——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-10594——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-93337HIGH7.8NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains an improper input validation vulnerability that allows loc...
CVE-2026-92993MEDIUM6.3A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of...
CVE-2026-92943HIGH8.1Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for ...
CVE-2026-92758MEDIUM5.5If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now