2026 CVE Vulnerabilities

53,154 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-35489HIGH7.3Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the...
CVE-2026-35488HIGH8.1Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Rec...
CVE-2026-35486HIGH7.5text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, he superbooga and...
CVE-2026-30460HIGH8.8Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in t...
CVE-2026-1078HIGH7.2An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R2...
CVE-2026-5373HIGH8.4An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is...
CVE-2026-4740HIGH8.2A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). ...
CVE-2026-3902HIGH7.5An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote att...
CVE-2026-35485HIGH7.5text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate...
CVE-2026-35464HIGH7.5pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTI...
CVE-2026-35463HIGH8.8pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTION...
CVE-2026-35457HIGH8.2libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous...
CVE-2026-35405HIGH7.5libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezv...
CVE-2026-33034HIGH7.5An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or u...
CVE-2026-24660HIGH8.1A heap-based buffer overflow vulnerability exists in the x3f_load_huffman functionality of LibRaw Commit d20315b. A spec...
CVE-2026-5627HIGH7.2A path traversal vulnerability exists in mintplex-labs/anything-llm versions up to and including 1.9.1, within the `Agen...
CVE-2026-35554HIGH8.7A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently del...
CVE-2026-5733HIGH8.8Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 149.0.2 and Thu...
CVE-2026-5732HIGH8.8Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox...
CVE-2026-32144HIGH7.4Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows OCSP designated-respo...
CVE-2026-22666HIGH8.6Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_s...
CVE-2026-31842HIGH8.7Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of t...
CVE-2026-34904HIGH7.5Cross-Site Request Forgery (CSRF) vulnerability in Analytify Simple Social Media Share Buttons allows Cross Site Request...
CVE-2026-34896HIGH7.5Cross-Site Request Forgery (CSRF) vulnerability in Analytify Under Construction, Coming Soon & Maintenance Mode allows C...
CVE-2026-34197HIGH8.8Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Br...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now