2026 CVE Vulnerabilities

53,154 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-34972HIGH8.8OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z...
CVE-2026-35203HIGH7.5ZLMediaKit is a streaming media service framework. the VP9 RTP payload parser in ext-codec/VP9Rtp.cpp reads multiple fie...
CVE-2026-35187HIGH7.7pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the parse_urls API fu...
CVE-2026-35185HIGH7.5HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to 25.0.0, the /server-status endpoint is pub...
CVE-2026-35182HIGH8.8Brave CMS is an open-source CMS. Prior to 2.0.6, this vulnerability is a missing authorization check found in the update...
CVE-2026-35176HIGH7.1openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exist...
CVE-2026-35172HIGH7.5Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore ...
CVE-2026-35170HIGH7.1openFPGALoader is a utility for programming FPGAs. In 1.1.1 and earlier, a heap-buffer-overflow read vulnerability exist...
CVE-2026-5678HIGH7.3A weakness has been identified in Totolink A7100RU 7.4cu.2313_b20191024. The affected element is the function setSchedul...
CVE-2026-5677HIGH7.3A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. Impacted is the function CsteSystem of the...
CVE-2026-5676HIGH7.3A vulnerability was identified in Totolink A8000R 5.9c.681_B20180413. This issue affects the function setLanguageCfg of ...
CVE-2026-5672HIGH7.3A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Affected by this issue is some unknown f...
CVE-2026-35470HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to 2.10.2, confronta_...
CVE-2026-35209HIGH7.5defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pa...
CVE-2026-35177HIGH7.1Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allo...
CVE-2026-35174HIGH7.2Chyrp Lite is an ultra-lightweight blogging engine. Prior to 2026.01, a path traversal vulnerability exists in the admin...
CVE-2026-35167HIGH8.1Kedro is a toolbox for production-ready data science. Prior to 1.3.0, the _get_versioned_path() method in kedro/io/core....
CVE-2026-35164HIGH8.8Brave CMS is an open-source CMS. Prior to 2.0.6, an unrestricted file upload vulnerability exists in the CKEditor upload...
CVE-2026-35050HIGH8.8text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.1.1, users can save ...
CVE-2026-35045HIGH8.1Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the...
CVE-2026-35043HIGH7.8BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4....
CVE-2026-5669HIGH7.3A vulnerability has been found in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Th...
CVE-2026-35042HIGH7.5fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (C...
CVE-2026-35037HIGH7.2Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, the GET /api/website/...
CVE-2026-35036HIGH7.5Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, Ech0 implements link ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now