2026 CVE Vulnerabilities

53,146 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-40031HIGH8.5MemProcFS before 5.17 contains multiple unsafe library-loading patterns that enable DLL and shared-library hijacking acr...
CVE-2026-40030HIGH8.4parseusbs before 1.9 contains an OS command injection vulnerability where the volume listing path argument (-v flag) is ...
CVE-2026-40029HIGH7.8parseusbs before 1.9 contains an OS command injection vulnerability in parseUSBs.py where LNK file paths are passed unsa...
CVE-2026-40027HIGH8.4ALEAPP (Android Logs Events And Protobuf Parser) through 3.4.0 contains a path traversal vulnerability in the NQ_Vault.p...
CVE-2026-40026HIGH7.1The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the pa...
CVE-2026-40024HIGH7.1The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write fi...
CVE-2026-5805HIGH7.3A weakness has been identified in code-projects Easy Blog Site up to 1.0. The impacted element is an unknown function of...
CVE-2026-5436HIGH8.1The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1....
CVE-2026-39891HIGH8.8PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like...
CVE-2026-39889HIGH7.5PraisonAI is a multi-agent teams system. Prior to 4.5.115, the A2U (Agent-to-User) event stream server in PraisonAI expo...
CVE-2026-39885HIGH7.5FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi libr...
CVE-2026-39883HIGH7OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed th...
CVE-2026-39881HIGH7.8Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans ...
CVE-2026-39860HIGH8.4Nix is a package manager for Linux and other Unix systems. A bug in the fix for CVE-2024-27297 allowed for arbitrary ove...
CVE-2026-39844HIGH7.5NiceGUI is a Python-based UI framework. Prior to 3.10.0, Since PurePosixPath only recognizes forward slashes (/) as path...
CVE-2026-5802HIGH7.3A vulnerability was identified in idachev mcp-javadc up to 1.2.4. Impacted is an unknown function of the component HTTP ...
CVE-2026-39863HIGH7.5Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds ...
CVE-2026-39862HIGH8.8Tophat is a mobile applications testing harness. Prior to 2.5.1, Tophat is affected by remote code execution via crafted...
CVE-2026-39859HIGH7.5LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, liquidjs 10.25.0 d...
CVE-2026-39412HIGH7.5LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.4, the sort_natural f...
CVE-2026-39411HIGH7.1LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to ...
CVE-2026-39362HIGH7.1InvenTree is an Open Source Inventory Management System. Prior to 1.2.7 and 1.3.0, when INVENTREE_DOWNLOAD_FROM_URL is e...
CVE-2026-35525HIGH7.5LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, for {% include %},...
CVE-2026-35478HIGH8.1InvenTree is an Open Source Inventory Management System. From 0.16.0 to before 1.2.7, any authenticated InvenTree user c...
CVE-2026-23869HIGH7.5A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now