2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33443MEDIUM5.9CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledg...
CVE-2026-62947MEDIUM4.9OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io aut...
CVE-2026-62355MEDIUM5.4TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Rea...
CVE-2026-62353MEDIUM5.4TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/p...
CVE-2026-62351HIGH7.5TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, source/libs/transport/sr...
CVE-2026-62350HIGH7.2TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a user wit...
CVE-2026-62349HIGH8.3TDengine is an open source, time-series database optimized for Internet of Things devices. In 3.4.1.6 and earlier, sourc...
CVE-2026-62348MEDIUM5.4TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allo...
CVE-2026-54443MEDIUM5.9Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssF...
CVE-2026-49988MEDIUM5.5Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_...
CVE-2026-49987HIGH8.8Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitSha...
CVE-2026-46485HIGH8.2Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated user...
CVE-2026-46421CRITICAL9.3The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-d...
CVE-2026-26032MEDIUM5.4The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a...
CVE-2026-15895HIGH8.4OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent ...
CVE-2026-15746MEDIUM6.9Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provide...
CVE-2026-12997HIGH7.5The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4...
CVE-2026-8055Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-48866. Reason: This candidate is a ...
CVE-2026-62948CRITICAL9.6OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN opt...
CVE-2026-62389Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as a duplicate of CVE-2026-48...
CVE-2026-61643MEDIUM5.9FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can...
CVE-2026-59258HIGH8.3immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that all...
CVE-2026-59255HIGH7.1BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes AP...
CVE-2026-58660HIGH8.1Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-d...
CVE-2026-58659HIGH8.4PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_st...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now