2026 CVE Vulnerabilities

56,900 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-47276MEDIUM6.5In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attac...
CVE-2026-47275LOW2.6In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `nni_mqttv5_msg_decode_connect()` allows a malicio...
CVE-2026-46701HIGH7.6Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.4.5, the MCP SSE server defaults to an e...
CVE-2026-46555HIGH7.1WhatsApp MCP Server is a Model Context Protocol (MCP) server for WhatsApp, enabling Claude to read and send WhatsApp mes...
CVE-2026-44978MEDIUM5.3xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the ...
CVE-2026-44178HIGH8.8xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within t...
CVE-2026-42218MEDIUM5.3xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login in...
CVE-2026-42210MEDIUM5.3Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that...
CVE-2026-41521CRITICAL9.1xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing s...
CVE-2026-41252CRITICAL9.8xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap...
CVE-2026-40187HIGH8.6In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) ...
CVE-2026-39879HIGH7.1Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb...
CVE-2026-39385HIGH7.1Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment vali...
CVE-2026-35591HIGH7.8libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before an...
CVE-2026-35590MEDIUM5.5libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and in...
CVE-2026-35217MEDIUM6.5NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the fi...
CVE-2026-35048CRITICAL9.8The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them d...
CVE-2026-33328MEDIUM5.5libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.1...
CVE-2026-33327HIGH7.8libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and includ...
CVE-2026-32825HIGH7.3dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-32824HIGH7.3dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-32823MEDIUM4.3dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-32821HIGH8.1dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-32820HIGH7.5dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...
CVE-2026-32819MEDIUM4.3dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now