2026 CVE Vulnerabilities

52,233 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-6560HIGH8.8A security vulnerability has been detected in H3C Magic B0 up to 100R002. This vulnerability affects the function Edit_B...
CVE-2026-41254HIGH7.5Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed ...
CVE-2026-32228HIGH7.5UI / API User with asset materialize permission could trigger dags they had no access to. Users are advised to migrate t...
CVE-2026-30912HIGH7.5In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to f...
CVE-2026-30898HIGH8.8An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause ...
CVE-2026-25917HIGH7.2Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing t...
CVE-2026-41253HIGH7.8In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working ...
CVE-2026-6518HIGH8.8The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload an...
CVE-2026-40491HIGH7.8gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack...
CVE-2026-40489HIGH8.6editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to ...
CVE-2026-35582HIGH8.8Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable ...
CVE-2026-40350HIGH8.8Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti...
CVE-2026-35465HIGH7.5SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the Se...
CVE-2026-40581HIGH8.1ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (S...
CVE-2026-40482HIGH7.1ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::ge...
CVE-2026-40480HIGH7.1ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoin...
CVE-2026-40349HIGH8.8Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti...
CVE-2026-40348HIGH7.7Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenti...
CVE-2026-40323HIGH7.5SP1 is a zero‑knowledge virtual machine that proves the correct execution of programs compiled for the RISC-V architectu...
CVE-2026-2262HIGH7.5The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and in...
CVE-2026-40481HIGH7.5monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoi...
CVE-2026-40476HIGH7.5graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCanBeMerged validation...
CVE-2026-40474HIGH7.6wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares per...
CVE-2026-40352HIGH8.8FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to N...
CVE-2026-40321HIGH8DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now