2026 CVE Vulnerabilities

68,769 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-92756MEDIUM5.5Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this prov...
CVE-2026-57846——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-54752CRITICAL9.6NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The vali...
CVE-2026-54716HIGH7.5Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earli...
CVE-2026-54692HIGH7.8SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P...
CVE-2026-54627CRITICAL9.8SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. I...
CVE-2026-54626CRITICAL9.8SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. I...
CVE-2026-54618CRITICAL9.4Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authoriza...
CVE-2026-54594MEDIUM5.3OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/d...
CVE-2026-54495MEDIUM4.3The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant wh...
CVE-2026-50285HIGH7.5Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs...
CVE-2026-50125HIGH7.5MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpo...
CVE-2026-45726HIGH7.6Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a st...
CVE-2026-45723LOW2.7Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.Creat...
CVE-2026-45720HIGH7Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML....
CVE-2026-92992MEDIUM6.3A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown functio...
CVE-2026-92230HIGH7.5Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container thr...
CVE-2026-90997HIGH7.4A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics b...
CVE-2026-55062HIGH8.4uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget...
CVE-2026-55061LOW1uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget...
CVE-2026-54649LOW2.1punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Pr...
CVE-2026-54617CRITICAL9.8GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote ...
CVE-2026-54571HIGH8.7ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3...
CVE-2026-54524HIGH7.1Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the ...
CVE-2026-54504HIGH8.8MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now