2026 CVE Vulnerabilities

43,273 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-71321HIGH7.5Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island ren...
CVE-2026-71320HIGH8.1Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject ...
CVE-2026-71316HIGH7.5Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries ...
CVE-2026-67865HIGH7.5S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attacker to cause a denia...
CVE-2026-67864HIGH7.5An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement ty...
CVE-2026-71315HIGH8.2Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules ...
CVE-2026-71314HIGH7.5Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated atta...
CVE-2026-71312HIGH8rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v...
CVE-2026-71309HIGH8.6rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40....
CVE-2026-34966HIGH8.3Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass...
CVE-2026-18411HIGH8.1The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication k...
CVE-2026-17583HIGH8.4The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be ed...
CVE-2026-70617HIGH8.6Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attac...
CVE-2026-70616HIGH7.1boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanentl...
CVE-2026-69111HIGH8.7Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers...
CVE-2026-68746HIGH8.8Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to...
CVE-2026-66881HIGH8.1Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with...
CVE-2026-66298HIGH8.8Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger se...
CVE-2026-66297HIGH8Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev l...
CVE-2026-55524HIGH7.5PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on...
CVE-2026-55523HIGH7.7PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.w...
CVE-2026-55522HIGH7.8PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of p...
CVE-2026-18958HIGH7.3A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a...
CVE-2026-18953HIGH8.8Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp...
CVE-2026-17556HIGH8.8A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to de...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now