2026 CVE Vulnerabilities

53,349 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-32857HIGH8.6Firecrawl version 2.8.0 and prior contain a server-side request forgery (SSRF) protection bypass vulnerability in the Pl...
CVE-2026-4867HIGH7.5Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separ...
CVE-2026-3108HIGH8.8Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-cont...
CVE-2026-33636HIGH7.6LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2026-33468HIGH8.1Kysely is a type-safe TypeScript SQL query builder. Prior to version 0.28.14, Kysely's `DefaultQueryCompiler.sanitizeStr...
CVE-2026-33442HIGH8.1Kysely is a type-safe TypeScript SQL query builder. In versions 0.28.12 and 0.28.13, the `sanitizeStringLiteral` method ...
CVE-2026-33430HIGH7.3Briefcase is a tool for converting a Python project into a standalone native application. Starting in version 0.3.0 and ...
CVE-2026-33416HIGH7.5LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ...
CVE-2026-32846HIGH7.5OpenClaw before 2026.3.28 contains a path traversal vulnerability in media parsing that allows attackers to read arbitra...
CVE-2026-27828HIGH7.5EVerest is an EV charging software stack. Prior to version 2026.02.0, ISO15118_chargerImpl::handle_session_setup uses v2...
CVE-2026-26074HIGH7EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to possible `std::map<std...
CVE-2026-28298HIGH8.1SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when...
CVE-2026-28297HIGH8.7SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when...
CVE-2026-27664HIGH8.7A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), SICORE Base syst...
CVE-2026-27663HIGH7.1A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), RTUM85 RTU Base ...
CVE-2026-26008HIGH7.5EVerest is an EV charging software stack. Versions prior to 2026.02.0 have an out-of-bounds access (std::vector) that le...
CVE-2026-23995HIGH7.8EVerest is an EV charging software stack. Prior to version 2026.02.0, stack-based buffer overflow in CAN interface initi...
CVE-2026-22790HIGH8.8EVerest is an EV charging software stack. Prior to version 2026.02.0, `HomeplugMessage::setup_payload` trusts `len` afte...
CVE-2026-22593HIGH7.8EVerest is an EV charging software stack. Prior to version 2026.02.0, an off-by-one check in IsoMux certificate filename...
CVE-2026-33413HIGH8.8etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.4.42, 3.5.28, and 3.6.9,...
CVE-2026-2511HIGH7.5The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `mu...
CVE-2026-2231HIGH7.2The Fluent Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in all vers...
CVE-2026-4887HIGH7.1A flaw was found in GIMP. This issue is a heap buffer over-read in GIMP PCX file loader due to an off-by-one error. A re...
CVE-2026-1961HIGH8A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket pr...
CVE-2026-24068HIGH8.8The VSL privileged helper does utilize NSXPC for IPC. The implementation of the "shouldAcceptNewConnection" function, wh...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now