2026 CVE Vulnerabilities

53,582 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-0954HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted DSB file in Digilent D...
CVE-2026-2229HIGH7.5ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_m...
CVE-2026-1528HIGH7.5ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's Byt...
CVE-2026-1526HIGH7.5The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessa...
CVE-2026-32274HIGH7.5Black is the uncompromising Python code formatter. Starting in version 24.3.0 and prior to version 26.3.1, Black writes ...
CVE-2026-3497HIGH7.5Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI...
CVE-2026-32247HIGH8.1Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2...
CVE-2026-32246HIGH7.1Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users wit...
CVE-2026-32242HIGH7.4Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32236HIGH7.5Backstage is an open framework for building developer portals. Prior to 0.27.1, a Server-Side Request Forgery (SSRF) vul...
CVE-2026-32231HIGH8.2ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields...
CVE-2026-32138HIGH8.2NEXULEAN is a cybersecurity portfolio & service platform for an Ethical Hacker, AI Enthusiast, and Penetration Tester. P...
CVE-2026-3841HIGH8.8A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5...
CVE-2026-32141HIGH7.5flatted is a circular JSON parser. Prior to 3.4.0, flatted's parse() function uses a recursive revive() phase to resolve...
CVE-2026-32140HIGH8.8Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an ...
CVE-2026-32137HIGH8.8Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasourc...
CVE-2026-32129HIGH8.7soroban-poseidon provides Poseidon and Poseidon2 cryptographic hash functions for Soroban smart contracts. Poseidon V1 (...
CVE-2026-32116HIGH8.1Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 ...
CVE-2026-28254HIGH7.5A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticate...
CVE-2026-28253HIGH7.5A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could a...
CVE-2026-26794HIGH8.8GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This v...
CVE-2026-28793HIGH8.4Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints...
CVE-2026-28791HIGH7.4Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS devel...
CVE-2026-28356HIGH7.5multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header...
CVE-2026-27940HIGH7.8llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now