2026 CVE Vulnerabilities

53,345 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-33953HIGH8.5LinkAce is a self-hosted archive to collect website links. Versions prior to 2.5.3 block direct requests to private IP l...
CVE-2026-33941HIGH8.2Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the Hand...
CVE-2026-33940HIGH8.1Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, a crafte...
CVE-2026-33939HIGH7.5Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a H...
CVE-2026-27309HIGH7.8Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbi...
CVE-2026-4976HIGH8.8A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. This vulnerability affects the function setWiFiGuestC...
CVE-2026-34046HIGH8.8Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.5.1, the `_read_flow` ...
CVE-2026-33938HIGH8.1Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@pa...
CVE-2026-33906HIGH7.2Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup...
CVE-2026-33895HIGH7.5Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ...
CVE-2026-33894HIGH7.5Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ...
CVE-2026-33891HIGH7.5Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version ...
CVE-2026-33881HIGH7.2Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Workspace env...
CVE-2026-33874HIGH7.8Gematik Authenticator securely authenticates users for login to digital health applications. Starting in version 4.12.0 ...
CVE-2026-4975HIGH8.8A vulnerability has been found in Tenda AC15 15.03.05.19. This affects the function formSetCfm of the file /goform/setcf...
CVE-2026-4974HIGH8.8A flaw has been found in Tenda AC7 15.03.06.44. Affected by this issue is the function fromSetSysTime of the file /gofor...
CVE-2026-34391HIGH7.5Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command process...
CVE-2026-34388HIGH7.5Fleet is open source device management software. Prior to 4.81.0, a denial-of-service vulnerability in Fleet's gRPC Laun...
CVE-2026-33872HIGH7.1elixir-nodejs provides an Elixir API for calling Node.js functions. A vulnerability in versions prior to 3.1.4 results i...
CVE-2026-33871HIGH7.5Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Fina...
CVE-2026-33870HIGH7.5Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.132.Final and 4.2.10.Fina...
CVE-2026-32241HIGH8.8Flannel is a network fabric for containers, designed for Kubernetes. The Flannel project includes an experimental Extens...
CVE-2026-31945HIGH7.7LibreChat is a ChatGPT clone with additional features. Versions 0.8.2-rc2 through 0.8.2 are vulnerable to a server-side ...
CVE-2026-31943HIGH8.5LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth...
CVE-2026-34386HIGH8.8Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now