2026 CVE Vulnerabilities

53,163 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-35042HIGH7.5fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (C...
CVE-2026-35037HIGH7.2Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, the GET /api/website/...
CVE-2026-35036HIGH7.5Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, Ech0 implements link ...
CVE-2026-35029HIGH8.8LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.0, the /config/updat...
CVE-2026-34992HIGH7.5Antrea is a Kubernetes networking solution intended to be Kubernetes native. Prior to 2.4.5 and 2.5.2, a missing encrypt...
CVE-2026-34986HIGH7.5Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including sup...
CVE-2026-34783HIGH8.1Ferret is a declarative system for working with web data. Prior to 2.0.0-alpha.4, a path traversal vulnerability in Ferr...
CVE-2026-5665HIGH7.3A security vulnerability has been detected in code-projects Online FIR System 1.0. Affected by this vulnerability is an ...
CVE-2026-34982HIGH8.2Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbi...
CVE-2026-34969HIGH7.5Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback f...
CVE-2026-34940HIGH8.8KubeAI is an AI inference operator for kubernetes. Prior to 0.23.2, the ollamaStartupProbeScript() function in internal/...
CVE-2026-34588HIGH7.8OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-34379HIGH7.1OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ...
CVE-2026-34217HIGH7.2SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, a scope modification vulnerability exists in @nyariv/sand...
CVE-2026-34211HIGH7.5SandboxJS is a JavaScript sandboxing library. Prior to 0.8.36, the @nyariv/sandboxjs parser contains unbounded recursion...
CVE-2026-34148HIGH7.5Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to 1.9.6, 1.10.5, 2.0.8,...
CVE-2026-33752HIGH8.6curl_cffi is the a Python binding for curl. Prior to 0.15.0, curl_cffi does not restrict requests to internal IP ranges,...
CVE-2026-21382HIGH7.8Memory Corruption when handling power management requests with improperly sized input/output buffers.
CVE-2026-21381HIGH7.5Transient DOS when receiving a service data frame with excessive length during device matching over a neighborhood aware...
CVE-2026-21380HIGH7.8Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.
CVE-2026-21378HIGH7.8Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor...
CVE-2026-21376HIGH7.8Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor...
CVE-2026-21375HIGH7.8Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.
CVE-2026-21374HIGH7.8Memory Corruption when processing auxiliary sensor input/output control commands with insufficient buffer size validatio...
CVE-2026-21373HIGH7.8Memory Corruption when accessing an output buffer without validating its size during IOCTL processing.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now