2026 CVE Vulnerabilities

53,599 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-32126HIGH8.1OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-32110HIGH8.3SiYuan is a personal knowledge management system. Prior to 3.6.0, the /api/network/forwardProxy endpoint allows authenti...
CVE-2026-32106HIGH7.2StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the REST API crea...
CVE-2026-32103HIGH7.2StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the POST /studioc...
CVE-2026-2368HIGH7.1An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user ca...
CVE-2026-1716HIGH7.1An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiyin...
CVE-2026-1715HIGH7.1An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiyin...
CVE-2026-0940HIGH8.4A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local pr...
CVE-2026-32098HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32097HIGH8.8PingPong is a platform for using large language models (LLMs) for teaching and learning. Prior to 7.27.2, an authenticat...
CVE-2026-32096HIGH8.6Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vul...
CVE-2026-31979HIGH7.8Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelbla...
CVE-2026-31958HIGH7.5Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only l...
CVE-2026-31954HIGH7.3Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lac...
CVE-2026-31895HIGH8.8WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, WeGIA (Web gerenciador para instituições ass...
CVE-2026-31894HIGH7.5WeGIA is a web manager for charitable institutions. In 3.6.5, The patched loadBackupDB() extracts tar.gz archives to a t...
CVE-2026-31889HIGH8.9Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration ...
CVE-2026-24510HIGH7.8Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Privilege Management vulnerabilit...
CVE-2026-31887HIGH7.5Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for una...
CVE-2026-31872HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-31870HIGH7.5cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib cl...
CVE-2026-31866HIGH7.5flagd is a feature flag daemon with a Unix philosophy. Prior to 0.14.2, flagd exposes OFREP (/ofrep/v1/evaluate/...) and...
CVE-2026-31862HIGH8.8Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1...
CVE-2026-31861HIGH8.8Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1...
CVE-2026-31858HIGH8.8Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now