2026 CVE Vulnerabilities

55,812 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-27942HIGH7.5fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li...
CVE-2026-27938HIGH7.7WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository con...
CVE-2026-27904HIGH7.5minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version...
CVE-2026-27903HIGH7.5minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version...
CVE-2026-27900HIGH7.7The Terraform Provider for Linode versions prior to v3.9.0 logged sensitive information including some passwords, StackS...
CVE-2026-27899HIGH8.8WireGuard Portal (or wg-portal) is a web-based configuration portal for WireGuard server management. Prior to version 2....
CVE-2026-1557HIGH7.5The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0 ...
CVE-2026-27896HIGH7.5The Go MCP SDK used Go's standard encoding/json.Unmarshal for JSON-RPC and MCP protocol message parsing in versions prio...
CVE-2026-27888HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to 6.7.3, an attacker who uses this vulnerability can cra...
CVE-2026-27831HIGH7.5rldns is an open source DNS server. Version 1.3 has a heap-based out-of-bounds read that leads to denial of service. Ver...
CVE-2026-27830HIGH8c3p0, a JDBC Connection pooling library, is vulnerable to attack via maliciously crafted Java-serialized objects and `ja...
CVE-2026-27829HIGH7.2Astro is a web framework. In versions 9.0.0 through 9.5.3, a bug in Astro's image pipeline allows bypassing `image.domai...
CVE-2026-27976HIGH8.8Zed, a code editor, has an extension installer allows tar/gzip downloads. Prior to version 0.224.4, the tar extractor (`...
CVE-2026-27967HIGH7.1Zed, a code editor, has a symlink escape vulnerability in versions prior to 0.225.9 in Agent file tools (`read_file`, `e...
CVE-2026-27821HIGH7.8GPAC is an open-source multimedia framework. In versions up to and including 26.02.0, a stack buffer overflow occurs dur...
CVE-2026-27818HIGH7.5TerriaJS-Server is a NodeJS Express server for TerriaJS, a library for building web-based geospatial data explorers. A v...
CVE-2026-27808HIGH8.6Mailpit is an email testing tool and API for developers. Prior to version 1.29.2, the Link Check API (/api/v1/message/{I...
CVE-2026-27800HIGH7.4Zed, a code editor, has a Zip Slip (Path Traversal) vulnerability exists in its extension archive extraction functionali...
CVE-2026-27798HIGH7.1ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-1...
CVE-2026-27635HIGH8.8Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on ...
CVE-2026-27633HIGH7.5TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 have a Denial of Servi...
CVE-2026-27630HIGH7.5TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Versions prior to version 2.02 are vulnerable to a De...
CVE-2026-26186HIGH8.8Fleet is open source device management software. A SQL injection vulnerability in versions prior to 4.80.1 allowed authe...
CVE-2026-27498HIGH8.8n8n is an open source workflow automation platform. Prior to versions 2.2.0 and 1.123.8, an authenticated user with perm...
CVE-2026-27497HIGH8.8n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now