2026 CVE Vulnerabilities

53,410 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-31903HIGH8.7The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc...
CVE-2026-22163HIGH7.8Requires malware code to misuse the DDK kernel module IOCTL interface. Such code can use the interface in an unsupporte...
CVE-2026-33172HIGH8.7Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.14 and 6.7.0, a stored XSS...
CVE-2026-33166HIGH7.5Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. The Allure report generator p...
CVE-2026-32887HIGH7.4Effect is a TypeScript framework that consists of several packages that work together to help build TypeScript applicati...
CVE-2026-23536HIGH7.5A security issue was discovered in the Feast Feature Server's `/read-document` endpoint that allows an unauthenticated r...
CVE-2026-33164HIGH7.5libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL u...
CVE-2026-33156HIGH7.8ScreenToGif is a screen recording tool. In versions from 2.42.1 and prior, ScreenToGif is vulnerable to DLL sideloading ...
CVE-2026-33155HIGH7.5DeepDiff is a project focused on Deep Difference and search of any Python data. From version 5.0.0 to before version 8.6...
CVE-2026-33154HIGH8.1dynaconf is a configuration management tool for Python. Prior to version 3.2.13, Dynaconf is vulnerable to Server-Side T...
CVE-2026-33151HIGH7.5Socket.IO is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions 3.3.5, 3....
CVE-2026-33150HIGH7.8libfuse is the reference implementation of the Linux FUSE. From version 3.18.0 to before version 3.18.2, a use-after-fre...
CVE-2026-33147HIGH7.8GMT is an open source collection of command-line tools for manipulating geographic and Cartesian data sets. In versions ...
CVE-2026-33144HIGH7.8GPAC is an open-source multimedia framework. Prior to commit 86b0e36, a heap-based buffer overflow (write) vulnerability...
CVE-2026-33143HIGH7.5OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook...
CVE-2026-33142HIGH8.1OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the fix for CVE-2026-3230...
CVE-2026-4504HIGH7.3A flaw has been found in eosphoros-ai db-gpt up to 0.7.5. This vulnerability affects unknown code of the file /api/v1/ed...
CVE-2026-4437HIGH7.5Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the...
CVE-2026-33139HIGH7.8PySpector is a static analysis security testing (SAST) Framework engineered for modern Python development workflows. PyS...
CVE-2026-33010HIGH8.8mcp-memory-service is an open-source memory backend for multi-agent systems. Prior to version 10.25.1, when the HTTP ser...
CVE-2026-32309HIGH7.5Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow expli...
CVE-2026-4493HIGH8.8A vulnerability was determined in Tenda A18 Pro 02.03.02.28. The impacted element is the function sub_423B50 of the file...
CVE-2026-4492HIGH8.8A vulnerability was found in Tenda A18 Pro 02.03.02.28. The affected element is the function set_qosMib_list of the file...
CVE-2026-31836HIGH8.1Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and...
CVE-2026-4491HIGH8.8A vulnerability has been found in Tenda A18 Pro 02.03.02.28. Impacted is the function fromSetIpMacBind of the file /gofo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now