2026 CVE Vulnerabilities

53,676 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-20882HIGH8.7The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc...
CVE-2026-20748HIGH8.6The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ...
CVE-2026-2754HIGH7.5Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. ...
CVE-2026-2753HIGH7.5An Absolute Path Traversal vulnerability exists in Navtor NavBox. The application exposes an HTTP service that fails to ...
CVE-2026-3589HIGH7.5The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allo...
CVE-2026-23925HIGH8.1An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configur...
CVE-2026-29074HIGH7.5SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version ...
CVE-2026-29073HIGH8.8SiYuan is a personal knowledge management system. Prior to version 3.6.0, the /api/query/sql lets a user run sql directl...
CVE-2026-29062HIGH7.5jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Pr...
CVE-2026-29059HIGH7.5Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to vers...
CVE-2026-29068HIGH7.5PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, there is a stack b...
CVE-2026-29039HIGH7.5changedetection.io is a free open source web page change detection tool. Prior to version 0.54.4, the changedetection.io...
CVE-2026-28801HIGH7.8Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, any ahk code cont...
CVE-2026-28800HIGH8Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, anyone with Disco...
CVE-2026-28799HIGH7.5PJSIP is a free and open source multimedia communication library written in C. Prior to version 2.17, a heap use-after-f...
CVE-2026-28683HIGH8.7Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, if...
CVE-2026-28681HIGH8.1Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From ve...
CVE-2026-28679HIGH7.5Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0,...
CVE-2026-28677HIGH8.2OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version...
CVE-2026-28676HIGH8.8OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version...
CVE-2026-28508HIGH8.6Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CS...
CVE-2026-28507HIGH7.2Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained...
CVE-2026-28429HIGH7.5Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871, a Path Traversal vulnerability was identified i...
CVE-2026-27603HIGH7.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-25888HIGH8.8Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now