2026 CVE Vulnerabilities

53,332 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-5177HIGH8.8A weakness has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Affected by this vulnerability is the function...
CVE-2026-34070HIGH7.5LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions i...
CVE-2026-34054HIGH7.8vcpkg is a free and open-source C/C++ package manager. Prior to version 3.6.1#3, vcpkg's Windows builds of OpenSSL set o...
CVE-2026-34043HIGH7.5Serialize JavaScript to a superset of JSON that includes regular expressions and functions. Prior to version 7.0.5, ther...
CVE-2026-34042HIGH8.2act is a project which allows for local running of github actions. Prior to version 0.2.86, act's built in actions/cache...
CVE-2026-34040HIGH7.8Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that all...
CVE-2026-33997HIGH8.1Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that all...
CVE-2026-4020HIGH7.5The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includi...
CVE-2026-5115HIGH7.5The PaperCut NG/MF (specifically, the embedded application for Konica Minolta devices) is vulnerable to session hijackin...
CVE-2026-30940HIGH7.2baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme ...
CVE-2026-30877HIGH7.2baserCMS is a website development framework. Prior to version 5.2.3, there is an OS command injection vulnerability in t...
CVE-2026-21861HIGH7.2baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerabi...
CVE-2026-5156HIGH8.8A vulnerability was determined in Tenda CH22 1.0.0.1. This impacts the function formQuickIndex of the file /goform/Quick...
CVE-2026-5155HIGH8.8A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function fromAdvSetWan of the file /goform/AdvSetWan o...
CVE-2026-5154HIGH8.8A vulnerability has been found in Tenda CH22 1.0.0.1/1.If. The impacted element is the function fromSetCfm of the file /...
CVE-2026-5130HIGH8.8The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up...
CVE-2026-5153HIGH8.8A flaw has been found in Tenda CH22 1.0.0.1. The affected element is the function FormWriteFacMac of the file /goform/Wr...
CVE-2026-33986HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in yuv_ensure_buffer() in libf...
CVE-2026-33985HIGH7.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap ...
CVE-2026-33984HIGH7.5FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in resize_vbar_entry() in libf...
CVE-2026-33982HIGH8.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, there is a heap-buffer-overflo...
CVE-2026-5152HIGH8.8A vulnerability was detected in Tenda CH22 1.0.0.1. Impacted is the function formCreateFileName of the file /goform/crea...
CVE-2026-32877HIGH8.2Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that c...
CVE-2026-32696HIGH7.5NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In NanoMQ version 0.24.6, after enabling auth.http...
CVE-2026-28228HIGH8.8OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. Prior to ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now