2026 CVE Vulnerabilities

55,159 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-3917HIGH8.8Use after free in Agents in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap c...
CVE-2026-3915HIGH8.8Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform an out of bou...
CVE-2026-3914HIGH8.8Integer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap ...
CVE-2026-3913HIGH8.8Heap buffer overflow in WebML in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit h...
CVE-2026-32132HIGH7.4ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a potential vulnerability exists in Z...
CVE-2026-32131HIGH7.7ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a vulnerability in Zitadel's Manageme...
CVE-2026-32130HIGH7.5ZITADEL is an open source identity management platform. From 2.68.0 to before 3.4.8 and 4.12.2, Zitadel provides a Syste...
CVE-2026-32127HIGH8.8OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-32126HIGH8.1OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0....
CVE-2026-32110HIGH8.3SiYuan is a personal knowledge management system. Prior to 3.6.0, the /api/network/forwardProxy endpoint allows authenti...
CVE-2026-32106HIGH7.2StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the REST API crea...
CVE-2026-32103HIGH7.2StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.3, the POST /studioc...
CVE-2026-2368HIGH7.1An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user ca...
CVE-2026-1716HIGH7.1An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiyin...
CVE-2026-1715HIGH7.1An input validation vulnerability was reported in the DeviceSettingsSystemAddin used in Lenovo Vantage and Lenovo Baiyin...
CVE-2026-0940HIGH8.4A potential improper initialization vulnerability was reported in the BIOS of some ThinkPads that could allow a local pr...
CVE-2026-32098HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-32097HIGH8.8PingPong is a platform for using large language models (LLMs) for teaching and learning. Prior to 7.27.2, an authenticat...
CVE-2026-32096HIGH8.6Plunk is an open-source email platform built on top of AWS SES. Prior to 0.7.0, a Server-Side Request Forgery (SSRF) vul...
CVE-2026-31979HIGH7.8Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Prior to 3.1.0 and 2.3.8, the himmelbla...
CVE-2026-31958HIGH7.5Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only l...
CVE-2026-31954HIGH7.3Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lac...
CVE-2026-31895HIGH8.8WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, WeGIA (Web gerenciador para instituições ass...
CVE-2026-31894HIGH7.5WeGIA is a web manager for charitable institutions. In 3.6.5, The patched loadBackupDB() extracts tar.gz archives to a t...
CVE-2026-31889HIGH8.9Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now