2026 CVE Vulnerabilities

55,151 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-30853HIGH8.2calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a p...
CVE-2026-2890HIGH7.5The Formidable Forms plugin for WordPress is vulnerable to a payment integrity bypass in all versions up to, and includi...
CVE-2026-29775HIGH8.2FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap out-of-bounds read/...
CVE-2026-29774HIGH8.2FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, a client-side heap buffer overflow occ...
CVE-2026-29079HIGH7.5Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment ...
CVE-2026-29078HIGH7.5Lexbor is a web browser engine library. Prior to 2.7.0, the ISO‑2022‑JP encoder in Lexbor fails to reset the temporary s...
CVE-2026-25819HIGH7.5HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23...
CVE-2026-25817HIGH8.8HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23...
CVE-2026-25076HIGH8.5Anchore Enterprise versions before 5.25.1 contain an SQL injection vulnerability in the GraphQL Reports API. An authenti...
CVE-2026-22199HIGH8.7Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi en...
CVE-2026-22193HIGH7.5wpDiscuz before 7.6.47 contains an SQL injection vulnerability in the getAllSubscriptions() function where string parame...
CVE-2026-22182HIGH8.7wpDiscuz before 7.6.47 contains an unauthenticated denial of service vulnerability that allows anonymous users to trigge...
CVE-2026-0957HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted file in Digilent DASYL...
CVE-2026-0956HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds read when loading a corrupted file in Digilent DASYLa...
CVE-2026-0955HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds read when loading a corrupted file in Digilent DASYLa...
CVE-2026-0954HIGH8.5There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted DSB file in Digilent D...
CVE-2026-2229HIGH7.5ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_m...
CVE-2026-1528HIGH7.5ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's Byt...
CVE-2026-1526HIGH7.5The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessa...
CVE-2026-32274HIGH7.5Black is the uncompromising Python code formatter. Starting in version 24.3.0 and prior to version 26.3.1, Black writes ...
CVE-2026-3497HIGH7.5Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI...
CVE-2026-32247HIGH8.1Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2...
CVE-2026-32246HIGH7.1Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users wit...
CVE-2026-32242HIGH7.4Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32236HIGH7.5Backstage is an open framework for building developer portals. Prior to 0.27.1, a Server-Side Request Forgery (SSRF) vul...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now