2026 CVE Vulnerabilities

56,307 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-25521HIGH8.8Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. In versions from 2.0.12 to...
CVE-2026-25512HIGH8.8Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.150, 25.0.82, a...
CVE-2026-25499HIGH7.5Terraform / OpenTofu Provider adds support for Proxmox Virtual Environment. Prior to version 0.93.1, in the SSH configur...
CVE-2026-0945HIGH8.8Privilege Defined With Unsafe Actions vulnerability in Drupal Role Delegation allows Privilege Escalation.This issue aff...
CVE-2026-25514HIGH8.8FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScr...
CVE-2026-25513HIGH8.8FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.81, FacturaScr...
CVE-2026-25161HIGH8.8Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the a...
CVE-2026-25160HIGH7.4Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the a...
CVE-2026-25157HIGH7.5OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the ...
CVE-2026-25143HIGH7.8melange allows users to build apk packages using declarative pipelines. From version 0.10.0 to before 0.40.3, an attacke...
CVE-2026-24884HIGH7.8Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts...
CVE-2026-24844HIGH8.8melange allows users to build apk packages using declarative pipelines. From version 0.3.0 to before 0.40.3, an attacker...
CVE-2026-24843HIGH8.4melange allows users to build apk packages using declarative pipelines. In version 0.11.3 to before 0.40.3, an attacker ...
CVE-2026-23897HIGH7.5Apollo Server is an open-source, spec-compliant GraphQL server that's compatible with any GraphQL client, including Apol...
CVE-2026-25140HIGH7.5apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1...
CVE-2026-25121HIGH7.5apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1...
CVE-2026-0536HIGH7.8A maliciously crafted GIF file, when parsed through Autodesk 3ds Max, can cause a Stack-Based Buffer Overflow vulnerabil...
CVE-2026-25532HIGH8ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1...
CVE-2026-22044HIGH8.8GLPI is a free asset and IT management software package. From version 0.85 to before 10.0.23, an authenticated user can ...
CVE-2026-21893HIGH7.2n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerab...
CVE-2026-25056HIGH8.8n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge no...
CVE-2026-25055HIGH8.1n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploade...
CVE-2026-23102HIGH7.1In the Linux kernel, the following vulnerability has been resolved: arm64/fpsimd: signal: Fix restoration of SVE contex...
CVE-2026-23099HIGH7.1In the Linux kernel, the following vulnerability has been resolved: bonding: limit BOND_MODE_8023AD to Ethernet devices...
CVE-2026-23098HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netrom: fix double-free in nr_route_frame() In nr_...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now