2026 CVE Vulnerabilities

56,076 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-27114HIGH7.5NanaZip is an open source file archive. Starting in version 5.0.1252.0 and prior to version 6.0.1630.0, circular `NextOf...
CVE-2026-26313HIGH7.5go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to version 1.17.0, an atta...
CVE-2026-26286HIGH8.5SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-26318HIGH8.8systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command...
CVE-2026-26280HIGH7.8systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection v...
CVE-2026-26278HIGH7.5fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based li...
CVE-2026-26267HIGH7.5soroban-sdk is a Rust SDK for Soroban contracts. Prior to versions 22.0.10, 23.5.2, and 25.1.1, the `#[contractimpl]` ma...
CVE-2026-26205HIGH7.1opa-envoy-plugun is a plugin to enforce OPA policies with Envoy. Versions prior to 1.13.2-envoy-2 have a vulnerability i...
CVE-2026-26202HIGH7.5Penpot is an open-source design tool for design and code collaboration. Prior to version 2.13.2, an authenticated user c...
CVE-2026-26201HIGH7.5emp3r0r is a C2 designed by Linux users for Linux environments. Prior to version 3.21.2, multiple shared maps are access...
CVE-2026-26200HIGH7.8HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an `h5` file parsed by HDF5 c...
CVE-2026-26189HIGH8.1Trivy Action runs Trivy as GitHub action to scan a Docker container image for vulnerabilities. A command injection vulne...
CVE-2026-26063HIGH8.8CediPay is a crypto-to-fiat app for the Ghanaian market. A vulnerability in CediPay prior to version 1.2.3 allows attack...
CVE-2026-26337HIGH8.8Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-s...
CVE-2026-2232HIGH7.5The Product Table and List Builder for WooCommerce Lite plugin for WordPress is vulnerable to time-based SQL Injection v...
CVE-2026-26336HIGH8.7Hyland Alfresco allows unauthenticated attackers to read arbitrary files from protected directories (like WEB-INF) via t...
CVE-2026-26016HIGH8.1Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1....
CVE-2026-25998HIGH7.5strongMan is a management interface for strongSwan, an OpenSource IPsec-based VPN. When storing credentials in the datab...
CVE-2026-24834HIGH8.8Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...
CVE-2026-1581HIGH7.5The wpForo Forum plugin for WordPress is vulnerable to time-based SQL Injection via the 'wpfob' parameter in all version...
CVE-2026-2274HIGH8.5A SSRF and Arbitrary File Read vulnerability in AppSheet Core in Google AppSheet prior to 2025-11-23 allows an authentic...
CVE-2026-26345HIGH8.6SPIP before 4.4.8 contains a stored cross-site scripting (XSS) vulnerability in the public area triggered in certain edg...
CVE-2026-25940HIGH8.1jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of properties and methods of the Acrofor...
CVE-2026-25755HIGH8.8jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method al...
CVE-2026-25535HIGH7.5jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the first argument of the `addImage` ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now