2026 CVE Vulnerabilities

55,826 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-25476HIGH7.5OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2026-25164HIGH8.1OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2026-24005HIGH7.6Kruise provides automated management of large-scale applications on Kubernetes. Prior to versions 1.8.3 and 1.7.5, PodPr...
CVE-2026-23627HIGH8.8OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2026-3194HIGH7A flaw has been found in Chia Blockchain 2.1.0. The affected element is the function send_transaction/get_private_key of...
CVE-2026-27850HIGH7.5Due to an improperly configured firewall rule, the router will accept any connection on the WAN port with the source por...
CVE-2026-27795HIGH7.4LangChain is a framework for building LLM-powered applications. Prior to version 1.1.8, a redirect-based Server-Side Req...
CVE-2026-25554HIGH8.3OpenSIPS versions 3.1 before 3.6.4 containing the auth_jwt module (prior to commit 3822d33) contain a SQL injection vuln...
CVE-2026-3192HIGH8.1A security vulnerability has been detected in Chia Blockchain 2.1.0. This issue affects the function _authenticate of th...
CVE-2026-27728HIGH8.8OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vu...
CVE-2026-27706HIGH7.7Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSR...
CVE-2026-20133HIGH7.5A vulnerability in Cisco Catalyst SD-WAN Software could allow an unauthenticated, remote attacker to view sensitive info...
CVE-2026-20128HIGH7.5A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an unauthenticat...
CVE-2026-20126HIGH7.8A vulnerability in Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker with low privileges to gai...
CVE-2026-20051HIGH7.4A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 Platform Switches and...
CVE-2026-20048HIGH7.7A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000 Series Fabric Switches in...
CVE-2026-20033HIGH7.4A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker...
CVE-2026-20010HIGH7.4A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticat...
CVE-2026-27730HIGH7.5esm.sh is a no-build content delivery network (CDN) for web development. Versions up to and including 137 have an SSRF v...
CVE-2026-27704HIGH7.5The Dart and Flutter SDKs provide software development kits for the Dart programming language. In versions of the Dart S...
CVE-2026-27701HIGH8.8LiveCode is an open-source, client-side code playground. Prior to commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11, LiveC...
CVE-2026-27700HIGH7.5Hono is a Web application framework that provides support for any JavaScript runtime. In versions 4.12.0 and 4.12.1, whe...
CVE-2026-22866HIGH7.5Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. In ve...
CVE-2026-3203HIGH7.5RF4CE Profile protocol dissector crash in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
CVE-2026-3202HIGH7.5NTS-KE protocol dissector crash in Wireshark 4.6.0 to 4.6.3 allows denial of service

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now