2026 CVE Vulnerabilities

48,516 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48047MEDIUM5.9XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to ...
CVE-2026-48026HIGH8.7lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of th...
CVE-2026-47249HIGH7.5Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling...
CVE-2026-47127MEDIUM6.5Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-UR...
CVE-2026-46409CRITICAL9.6OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to v...
CVE-2026-64676MEDIUM5.7Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In ...
CVE-2026-58262HIGH7.1Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification cou...
CVE-2026-48170CRITICAL9.1`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM ...
CVE-2026-48169HIGH8.8PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization fa...
CVE-2026-47243CRITICAL9.2Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...
CVE-2026-46405MEDIUM5.3OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth m...
CVE-2026-45808HIGH7.1OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide...
CVE-2026-11743MEDIUM6.6The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length o...
CVE-2026-11742LOW3.6The kernel queue helper z_queue_node_peek() in kernel/queue.c dereferences a node taken from a queue's data_q list, read...
CVE-2026-9031MEDIUM6.8An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied da...
CVE-2026-9030MEDIUM6.8A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction han...
CVE-2026-71381MEDIUM4Adobe Genuine Software Integrity Service on Windows is affected by an Incorrect Authorization vulnerability that could r...
CVE-2026-70624Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-70623Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-69207MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in COR...
CVE-2026-66061HIGH7.1Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS...
CVE-2026-66060HIGH7.1Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Co...
CVE-2026-59717MEDIUM4.3Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.6.1, the Andr...
CVE-2026-54338MEDIUM5.3JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. Prior to 5.5.0, invalid in...
CVE-2026-50540CRITICAL9.6Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now