2026 CVE Vulnerabilities

68,634 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32641HIGH7.5Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.0.0, src/handlers/ht...
CVE-2026-93765CRITICAL9.1Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. In...
CVE-2026-93758HIGH8.1An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a ...
CVE-2026-93579MEDIUM6.5A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, s...
CVE-2026-93559HIGH7.3A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This aff...
CVE-2026-93534MEDIUM6.3A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file ap...
CVE-2026-93533MEDIUM6.3A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivi...
CVE-2026-93338MEDIUM5.3Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows una...
CVE-2026-91149HIGH7.5A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustain...
CVE-2026-91147MEDIUM5.9A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Serv...
CVE-2026-91142LOW3.6A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offse...
CVE-2026-85497CRITICAL9.8CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insu...
CVE-2026-85478LOW3.5A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical...
CVE-2026-81505HIGH7.1Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID}...
CVE-2026-81321CRITICAL9.8CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker w...
CVE-2026-77616MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77610MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77609MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77608MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77607MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77606MEDIUM6.1Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ...
CVE-2026-77339MEDIUM5.1Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listen...
CVE-2026-77301HIGH7.5adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEnt...
CVE-2026-77240CRITICAL9.9WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security...
CVE-2026-77239HIGH8.1WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation write routes...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now