2026 CVE Vulnerabilities

48,532 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-64663MEDIUM6.5Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-sup...
CVE-2026-64662MEDIUM6.5Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont...
CVE-2026-64655LOW2.1GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, gh attestation verify  builds the certificate S...
CVE-2026-64654MEDIUM5.3GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed ex...
CVE-2026-64653MEDIUM5.1GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable pat...
CVE-2026-64652LOW3.3GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, gh auth status masked only the characte...
CVE-2026-63725HIGH8.6sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a ta...
CVE-2026-63637HIGH8.6Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter....
CVE-2026-62857HIGH8.8Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the...
CVE-2026-61632MEDIUM5.3PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.2...
CVE-2026-5857CRITICAL9.2Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking ...
CVE-2026-5856HIGH7.1Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no pack...
CVE-2026-5855HIGH8.7Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer lengt...
CVE-2026-5336MEDIUM6.8The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template ren...
CVE-2026-54717MEDIUM5.4Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable...
CVE-2026-53984CRITICAL9.1Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerabilit...
CVE-2026-53983CRITICAL9.2Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital...
CVE-2026-50159MEDIUM5.3Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 ...
CVE-2026-49391MEDIUM5.1Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported co...
CVE-2026-48088CRITICAL9.4OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48087CRITICAL9.8OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48086CRITICAL9.9OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48085CRITICAL9.8OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...
CVE-2026-48084HIGH7.4OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions pri...
CVE-2026-48083MEDIUM6.5OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now