2026 CVE Vulnerabilities

53,674 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-25071HIGH7.5XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain a missing authentication vulnerability i...
CVE-2026-30244HIGH7.5Plane is an an open-source project management tool. Prior to version 1.2.2, unauthenticated attackers can enumerate work...
CVE-2026-30242HIGH8.5Plane is an an open-source project management tool. Prior to version 1.2.3, the webhook URL validation in plane/app/seri...
CVE-2026-30241HIGH8.2Mercurius is a GraphQL adapter for Fastify. Prior to version 16.8.0, Mercurius fails to enforce the configured queryDept...
CVE-2026-27137HIGH7.5When verifying a certificate chain which contains a certificate containing multiple email address constraints which shar...
CVE-2026-25679HIGH7.5url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
CVE-2026-30230HIGH7.5Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to version 1....
CVE-2026-30229HIGH7.2Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-30223HIGH8.8OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, when JWT authentica...
CVE-2026-29795HIGH7.5stellar-xdr is a library and CLI containing types and functionality for working with Stellar XDR. Prior to version 25.0....
CVE-2026-29789HIGH8.8Vito is a self-hosted web application that helps manage servers and deploy PHP applications into production servers. Pri...
CVE-2026-29788HIGH7.5TSPortal is the WikiTide Foundation’s in-house platform used by the Trust and Safety team to manage reports, investigati...
CVE-2026-29182HIGH7.2Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-30846HIGH7.5Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the globalwebhooks publication e...
CVE-2026-30845HIGH8.2Wekan is an open source kanban tool built with Meteor. In versions 8.31.0 through 8.33, the board composite publication ...
CVE-2026-30844HIGH8.1Wekan is an open source kanban tool built with Meteor. Versions 8.32 and 8.33 are vulnerable to Server-Side Request Forg...
CVE-2026-29178HIGH7.7Lemmy, a link aggregator and forum for the fediverse, is vulnerable to server-side request forgery via a dependency on a...
CVE-2026-29091HIGH8.1Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a ...
CVE-2026-29089HIGH8.8TimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgres extension. From ve...
CVE-2026-29087HIGH7.5@hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server...
CVE-2026-29783HIGH7.8The shell tool within GitHub Copilot CLI versions prior to and including 0.0.422 can allow arbitrary code execution thro...
CVE-2026-29064HIGH8.2Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal...
CVE-2026-27764HIGH8.6The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ...
CVE-2026-26018HIGH7.5CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDN...
CVE-2026-24696HIGH8.7The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now