2026 CVE Vulnerabilities

53,393 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-32948HIGH7.8sbt is a build tool for Scala, Java, and others. From version 0.9.5 to before version 1.12.7, on Windows, sbt uses Proce...
CVE-2026-22559HIGH8.8An Improper Input Validation vulnerability in UniFi Network Server may allow unauthorized access to an account if the ac...
CVE-2026-33539HIGH7.2Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33538HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33508HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33498HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-33417HIGH7.1Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in ...
CVE-2026-30932HIGH8.8Froxlor is open source server administration software. Prior to version 2.3.5, the DomainZones.add API endpoint (accessi...
CVE-2026-29772HIGH7.5Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full reque...
CVE-2026-23921HIGH8.7A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiS...
CVE-2026-23920HIGH7.7Host and event action script input is validated with a regex (set by the administrator), but the validation runs in mult...
CVE-2026-23919HIGH7.1For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript repro...
CVE-2026-1995HIGH7.8In versions before 7.0.0.64, IDrive’s id_service.exe process runs with elevated privileges and regularly reads from seve...
CVE-2026-33399HIGH7.7Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in v...
CVE-2026-33157HIGH7.2Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.13, a Remote Code Execution (RC...
CVE-2026-32854HIGH7.5LibVNCServer versions 0.9.15 and prior (fixed in commit dc78dee) contain null pointer dereference vulnerabilities in the...
CVE-2026-32853HIGH8.1LibVNCServer versions 0.9.15 and prior (fixed in commit 009008e) contain a heap out-of-bounds read vulnerability in the ...
CVE-2026-33679HIGH7.4Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, the `DownloadImage` function in ...
CVE-2026-33678HIGH8.1Vikunja is an open-source self-hosted task management platform. Prior to version 2.2.1, `TaskAttachment.ReadOne()` queri...
CVE-2026-33668HIGH8.1Vikunja is an open-source self-hosted task management platform. Starting in version 0.18.0 and prior to version 2.2.1, w...
CVE-2026-33336HIGH8.8Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, t...
CVE-2026-33335HIGH8Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, t...
CVE-2026-29839HIGH8.8DedeCMS v5.7.118 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability in /sys_task_add.php.
CVE-2026-4775HIGH7.8A flaw was found in the libtiff library. A remote attacker could exploit a signed integer overflow vulnerability in the ...
CVE-2026-33554HIGH7.5ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. The Intelligent Platform Manag...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now