2026 CVE Vulnerabilities

48,530 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-71438LOW2.4Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 ...
CVE-2026-71437MEDIUM6.5Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11....
CVE-2026-71436MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10....
CVE-2026-71435MEDIUM6.1Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automag...
CVE-2026-71434MEDIUM5.3Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms...
CVE-2026-71433MEDIUM5.3LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoin...
CVE-2026-71430MEDIUM6.2node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function...
CVE-2026-71327HIGH7.6Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes...
CVE-2026-71326LOW2.1Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth...
CVE-2026-71325MEDIUM4.8Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25...
CVE-2026-71324HIGH7Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default H...
CVE-2026-70640HIGH7.3llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrap...
CVE-2026-70639MEDIUM6.8llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper w...
CVE-2026-70638HIGH8.5llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where th...
CVE-2026-70636HIGH8.7Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access th...
CVE-2026-70635HIGH7.1TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authentica...
CVE-2026-70634HIGH8.1TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression revers...
CVE-2026-70633HIGH7.1TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compres...
CVE-2026-70632HIGH8.5FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native G...
CVE-2026-70631MEDIUM6.8FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in ...
CVE-2026-70630MEDIUM6.8FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na...
CVE-2026-70629MEDIUM6.8FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the na...
CVE-2026-70628HIGH8.5FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtit...
CVE-2026-70559HIGH8.7Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation t...
CVE-2026-70558CRITICAL9.8Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now