2026 CVE Vulnerabilities

56,283 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-21532HIGH8.2Azure Function Information Disclosure Vulnerability
CVE-2026-1523HIGH8.7Path Traversal vulnerability in Digitek ADT1100 and Digitek DT950 from PRIMION DIGITEK, S.L.U (Azkoyen Group). This vuln...
CVE-2026-23572HIGH7.2Improper access control in the TeamViewer Full and Host clients (Windows, macOS, Linux) prior version 15.74.5 allows an ...
CVE-2026-1294HIGH7.2The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t...
CVE-2026-1953HIGH8.2Nukegraphic CMS v3.1.2 contains a stored cross-site scripting (XSS) vulnerability in the user profile edit functionality...
CVE-2026-25585HIGH7.8iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color ...
CVE-2026-22038HIGH8.1AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut...
CVE-2026-25584HIGH7.8iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color ...
CVE-2026-25583HIGH7.8iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color ...
CVE-2026-25582HIGH7.8iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color ...
CVE-2026-25575HIGH7.5NavigaTUM is a website and API to search for rooms, buildings and other places. Prior to commit 86f34c7, there is a path...
CVE-2026-25546HIGH7.8Godot MCP is a Model Context Protocol (MCP) server for interacting with the Godot game engine. Prior to version 0.1.1, a...
CVE-2026-25541HIGH7.5Bytes is a utility library for working with bytes. From version 1.2.1 to before 1.11.1, Bytes is vulnerable to integer o...
CVE-2026-25539HIGH7.2SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not valid...
CVE-2026-25538HIGH8.8Devtron is an open source tool integration platform for Kubernetes. In version 2.0.0 and prior, a vulnerability exists i...
CVE-2026-25537HIGH7.5jsonwebtoken is a JWT lib in rust. Prior to version 10.3.0, there is a Type Confusion vulnerability in jsonwebtoken, spe...
CVE-2026-25536HIGH7.1MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to...
CVE-2026-25521HIGH8.8Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to...
CVE-2026-25512HIGH8.8Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, a...
CVE-2026-25499HIGH7.5Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configur...
CVE-2026-0945HIGH8.8Privilege Defined With Unsafe Actions vulnerability in Drupal Role Delegation allows Privilege Escalation.This issue aff...
CVE-2026-25514HIGH8.8FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScr...
CVE-2026-25513HIGH8.8FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScr...
CVE-2026-25161HIGH8.8Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the a...
CVE-2026-25160HIGH7.4Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now