2026 CVE Vulnerabilities

53,332 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-27599HIGH7.2CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati...
CVE-2026-27018HIGH7.5Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can ...
CVE-2026-25627HIGH7.5NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.24.8, NanoMQ’s MQTT-over-WebSoc...
CVE-2026-5150HIGH7.3A security vulnerability has been detected in code-projects Accounting System 1.0. This issue affects some unknown proce...
CVE-2026-31831HIGH7.5Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/...
CVE-2026-21710HIGH7.5A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `_...
CVE-2026-5147HIGH7.3A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This affects an unknown part of the file /admin...
CVE-2026-3991HIGH7.8Symantec Data Loss Prevention Windows Endpoint, prior to 25.1 MP1, 16.1 MP2, 16.0 RU2 HF9, 16.0 RU1 MP1 HF12, and 16.0 M...
CVE-2026-3502HIGH7.8TrueConf Client downloads application update code and applies it without performing verification. An attacker who is abl...
CVE-2026-34714HIGH8.6Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configurat...
CVE-2026-29925HIGH7.7Invoice Ninja v5.12.46 and v5.12.48 is vulnerable to Server-Side Request Forgery (SSRF) in CheckDatabaseRequest.php.
CVE-2026-29924HIGH7.6Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the a...
CVE-2026-4046HIGH7.5The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when convertin...
CVE-2026-33028HIGH7.5Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerabl...
CVE-2026-30077HIGH7.5OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But ...
CVE-2026-29872HIGH8.2A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80...
CVE-2026-29954HIGH7.6In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing th...
CVE-2026-34472HIGH7.1Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows u...
CVE-2026-33643HIGH7.4SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the mysqlColumnAsInsert function in file pl...
CVE-2026-2285HIGH7.5CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validati...
CVE-2026-29953HIGH7.4SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the columnAsInsert function in file plugins...
CVE-2026-5165HIGH7.8A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it...
CVE-2026-33373HIGH8.8An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability e...
CVE-2026-3321HIGH8.7A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1/answer/{EVENTID}/{TIME...
CVE-2026-28527HIGH7.3BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAY...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now