2026 CVE Vulnerabilities

68,802 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-90997HIGH7.4A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics b...
CVE-2026-55062HIGH8.4uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget...
CVE-2026-55061LOW1uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget...
CVE-2026-54649LOW2.1punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Pr...
CVE-2026-54617CRITICAL9.8GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote ...
CVE-2026-54571HIGH8.7ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3...
CVE-2026-54524HIGH7.1Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the ...
CVE-2026-54504HIGH8.8MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13...
CVE-2026-54451HIGH8.2Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attack...
CVE-2026-54253HIGH8.2TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in pac...
CVE-2026-54239HIGH8.8Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertex...
CVE-2026-52852MEDIUM6.5Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups a...
CVE-2026-52851HIGH7.1Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an ob...
CVE-2026-52727HIGH7.2lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publica...
CVE-2026-49292NONE0Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBV...
CVE-2026-47252CRITICAL9Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access...
CVE-2026-19477HIGH7.8There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq).  This...
CVE-2026-92927MEDIUM5.3A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing o...
CVE-2026-92926HIGH7.3A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepar...
CVE-2026-89038MEDIUM6.2Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co...
CVE-2026-54677MEDIUM6.5Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, authenticated users who are not members of ...
CVE-2026-54676MEDIUM6.5Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, users with personal API tokens can retrieve...
CVE-2026-54551MEDIUM4.3WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management. From 2.2.0 until 2....
CVE-2026-54546MEDIUM5CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22....
CVE-2026-54446HIGH8.1NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now