2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-48026HIGH8.7lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of th...
CVE-2026-47249HIGH7.5Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling...
CVE-2026-58262HIGH7.1Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification cou...
CVE-2026-48169HIGH8.8PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization fa...
CVE-2026-45808HIGH7.1OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide...
CVE-2026-66061HIGH7.1Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.0, the iOS...
CVE-2026-66060HIGH7.1Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.5.3, the Co...
CVE-2026-47664HIGH8.6Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ...
CVE-2026-47663HIGH8.7Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ...
CVE-2026-47662HIGH8.7Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ...
CVE-2026-65819HIGH7.5gopacket provides packet processing capabilities for Go. Through version 1.7.0, multiple layer decoders use attacker-con...
CVE-2026-62296HIGH7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11...
CVE-2026-62295HIGH7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11...
CVE-2026-48007HIGH8.6Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to ...
CVE-2026-47661HIGH8.7Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ...
CVE-2026-47660HIGH8.7Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ...
CVE-2026-47659HIGH8.7Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior ...
CVE-2026-15972HIGH7.5Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of servi...
CVE-2026-71847HIGH8.7Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consume...
CVE-2026-70561HIGH7.1TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user,...
CVE-2026-48098HIGH7.3NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Vers...
CVE-2026-48097HIGH7.8NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Vers...
CVE-2026-19231HIGH7.3A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects ...
CVE-2026-11430HIGH7.3Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook featu...
CVE-2026-64638HIGH8.9WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malici...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now