2026 CVE Vulnerabilities

55,163 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-31889HIGH8.9Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration ...
CVE-2026-24510HIGH7.8Dell Alienware Command Center (AWCC), versions prior to 6.12.24.0, contain an Improper Privilege Management vulnerabilit...
CVE-2026-31887HIGH7.5Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for una...
CVE-2026-31872HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a...
CVE-2026-31870HIGH7.5cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib cl...
CVE-2026-31866HIGH7.5flagd is a feature flag daemon with a Unix philosophy. Prior to 0.14.2, flagd exposes OFREP (/ofrep/v1/evaluate/...) and...
CVE-2026-31862HIGH8.8Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1...
CVE-2026-31861HIGH8.8Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1...
CVE-2026-31858HIGH8.8Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() ...
CVE-2026-31857HIGH8.8Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in t...
CVE-2026-30226HIGH7.5Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the ...
CVE-2026-31854HIGH8.8Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted i...
CVE-2026-31839HIGH7.5Striae is a firearms examiner's comparison companion. A high-severity integrity bypass vulnerability existed in Striae's...
CVE-2026-30868HIGH8.1OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, multiple OPNsense MVC API endpoints perform ...
CVE-2026-30239HIGH7.1OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the wor...
CVE-2026-20163HIGH7.2In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.251...
CVE-2026-20074HIGH7.4A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR...
CVE-2026-20046HIGH8.8A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticate...
CVE-2026-20040HIGH8.8A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary co...
CVE-2026-31892HIGH8.1Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 2....
CVE-2026-28229HIGH7.5Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t...
CVE-2026-27897HIGH7.1Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability e...
CVE-2026-22248HIGH8.8GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track...
CVE-2026-21888HIGH7.5NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. MQTT v5 Variable Byte Integer parsing out-of-bound...
CVE-2026-1497HIGH7.2Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now