2026 CVE Vulnerabilities

43,031 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-73222HIGH8.8Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio ...
CVE-2026-72742HIGH8.6DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attacke...
CVE-2026-69119HIGH8.3Taubyte Tau v1.1.10 contains a missing authorization vulnerability in the services/auth HTTP service that allows any aut...
CVE-2026-69115HIGH7.1OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-o...
CVE-2026-48809HIGH7.5python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have tw...
CVE-2026-48802HIGH7.5python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an atta...
CVE-2026-18712HIGH8.1An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileg...
CVE-2026-18711HIGH7.1An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to ...
CVE-2026-18706HIGH7.5An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation ...
CVE-2026-18705HIGH7.1An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view ...
CVE-2026-18704HIGH7.1An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perfor...
CVE-2026-18701HIGH7.1An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server ...
CVE-2026-18697HIGH8.7An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) proce...
CVE-2026-18696HIGH7An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to ...
CVE-2026-18695HIGH7.1An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could...
CVE-2026-18694HIGH7.1An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to caus...
CVE-2026-18693HIGH7.6An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges ...
CVE-2026-18692HIGH8.8An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privil...
CVE-2026-18690HIGH8.1An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action ag...
CVE-2026-18688HIGH7.1An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory ...
CVE-2026-18687HIGH7.1MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request para...
CVE-2026-15426HIGH8.8The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v...
CVE-2026-73218HIGH7.7Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in A...
CVE-2026-73217HIGH7.7Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in A...
CVE-2026-73215HIGH7.1Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now