2026 CVE Vulnerabilities

56,275 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-25754HIGH7.2AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a prototype pollution vulnerab...
CVE-2026-25644HIGH7.5DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM a...
CVE-2026-2068HIGH8.8A vulnerability was detected in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/for...
CVE-2026-25758HIGH7.5Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Comm...
CVE-2026-25732HIGH7.5NiceGUI is a Python-based UI framework. Prior to 3.7.0, NiceGUI's FileUpload.name property exposes client-supplied filen...
CVE-2026-25533HIGH8.8Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to 2.10.1, the existing layers o...
CVE-2026-2067HIGH8.8A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy o...
CVE-2026-2066HIGH8.8A weakness has been identified in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/formIpG...
CVE-2026-25731HIGH7.8calibre is an e-book manager. Prior to 9.2.0, a Server-Side Template Injection (SSTI) vulnerability in Calibre's Templit...
CVE-2026-25636HIGH7.8calibre is an e-book manager. In 9.1.0 and earlier, a path traversal vulnerability in Calibre's EPUB conversion allows a...
CVE-2026-25635HIGH8.6calibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains a path traversal vulnerability that allows a...
CVE-2026-25634HIGH7.8iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color ...
CVE-2026-25628HIGH8.8Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append t...
CVE-2026-25593HIGH8.4OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket...
CVE-2026-25580HIGH8.6Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 0.0.26 to befor...
CVE-2026-2065HIGH8.8A security flaw has been discovered in Flycatcher Toys smART Pixelator 2.0. Affected by this issue is some unknown funct...
CVE-2026-2063HIGH7.2A security flaw has been discovered in D-Link DIR-823X 250416. This vulnerability affects unknown code of the file /gofo...
CVE-2026-2062HIGH7.5A vulnerability was identified in Open5GS up to 2.7.6. This affects the function sgwc_s5c_handle_modify_bearer_response/...
CVE-2026-25751HIGH7.5FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. An information disclosure vulnerability in FUX...
CVE-2026-25650HIGH7.5MCP Salesforce Connector is a Model Context Protocol (MCP) server implementation for Salesforce integration. Prior to 0....
CVE-2026-23989HIGH8.1REVA is an interoperability platform. Prior to 2.42.3 and 2.40.3, a bug in the GRPC authorization middleware of the "Rev...
CVE-2026-2061HIGH7.2A vulnerability was determined in D-Link DIR-823X 250416. Affected by this issue is the function sub_424D20 of the file ...
CVE-2026-25724HIGH7.5Claude Code is an agentic coding tool. Prior to version 2.1.7, Claude Code failed to strictly enforce deny rules configu...
CVE-2026-24851HIGH8.8OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z...
CVE-2026-24135HIGH8.1Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now