2026 CVE Vulnerabilities

64,775 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-62278HIGH8.1LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authen...
CVE-2026-61552HIGH7.2Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes atta...
CVE-2026-61551HIGH8.6Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaus...
CVE-2026-33625HIGH8.8LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 conta...
CVE-2026-32641HIGH7.5Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.0.0, src/handlers/ht...
CVE-2026-93758HIGH8.1An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a ...
CVE-2026-93559HIGH7.3A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This aff...
CVE-2026-91149HIGH7.5A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustain...
CVE-2026-81505HIGH7.1Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID}...
CVE-2026-77301HIGH7.5adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEnt...
CVE-2026-77239HIGH8.1WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation write routes...
CVE-2026-73863HIGH7NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT v5 nmq_subinfo_decode() function in nng/src/sp/pro...
CVE-2026-63349HIGH7AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In ...
CVE-2026-62943HIGH8.7btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_fil...
CVE-2026-61833HIGH8.1zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior ...
CVE-2026-61672HIGH7.1Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in p...
CVE-2026-61548HIGH8.1Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseS...
CVE-2026-58197HIGH8.8ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to Too...
CVE-2026-55556HIGH8.2Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_aut...
CVE-2026-46655HIGH7.8virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits...
CVE-2026-93690HIGH7.5uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely ...
CVE-2026-93688HIGH7.5SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstra...
CVE-2026-93687HIGH7.5braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attack...
CVE-2026-88259HIGH7.5CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenti...
CVE-2026-86520HIGH7.5Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now