2026 CVE Vulnerabilities

56,373 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-1327HIGH8.8A security vulnerability has been detected in Totolink NR1800X 9.1.0u.6279_B20210910. This issue affects the function se...
CVE-2026-1326HIGH8.8A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. This vulnerability affects the function setWan...
CVE-2026-1102HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.6.4, 18.7 before 18.7.2, and 1...
CVE-2026-0723HIGH7.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.4, 18.7 before 18.7.2, and 1...
CVE-2026-1330HIGH8.7MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote at...
CVE-2026-24038HIGH8.1Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the OTP handling logic has ...
CVE-2026-24010HIGH8Horilla is a free and open source Human Resource Management System (HRMS). A critical File Upload vulnerability in versi...
CVE-2026-24006HIGH7.5Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versio...
CVE-2026-24001HIGH7.5jsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, 4.0.4, and 3.5.1, attempting to...
CVE-2026-23992HIGH7.5go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a com...
CVE-2026-23991HIGH7.5go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if th...
CVE-2026-23967HIGH7.5sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A signature mal...
CVE-2026-23965HIGH7.5sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. A signature for...
CVE-2026-23962HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. Mastodon versions before v4.3.18, v4.4.12, a...
CVE-2026-23957HIGH7.5seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versio...
CVE-2026-23956HIGH7.5seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versio...
CVE-2026-23699HIGH8.6AP180 series with firmware versions prior to AP_RGOS 11.9(4)B1P8 contains an OS command injection vulnerability. If this...
CVE-2026-23952HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and belo...
CVE-2026-24046HIGH7.1Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilit...
CVE-2026-23986HIGH7.1Copier is a library and CLI app for rendering project templates. Prior to version 9.11.2, Copier suggests that it's safe...
CVE-2026-23737HIGH7.5seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versio...
CVE-2026-23526HIGH8.8CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.0.0 through 2.54.0...
CVE-2026-23517HIGH8.1Fleet is open source device management software. A broken access control issue in versions prior to 4.78.3, 4.77.1, 4.76...
CVE-2026-22822HIGH8.8External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete...
CVE-2026-22598HIGH7.1ManageIQ is an open-source management platform. A flaw was found in the ManageIQ API prior to version radjabov-2 where a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now