2026 CVE Vulnerabilities

56,866 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-0822HIGH8.8A vulnerability was identified in quickjs-ng quickjs up to 0.11.0. This issue affects the function js_typed_array_sort o...
CVE-2026-22777HIGH7.5ComfyUI-Manager is an extension designed to enhance the usability of ComfyUI. Prior to versions 3.39.2 and 4.0.5, an att...
CVE-2026-22773HIGH7.5vLLM is an inference and serving engine for large language models (LLMs). In versions from 0.6.4 to before 0.12.0, users...
CVE-2026-22700HIGH7.5RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for...
CVE-2026-22699HIGH7.5RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for...
CVE-2026-22698HIGH7.5RustCrypto: Elliptic Curves is general purpose Elliptic Curve Cryptography (ECC) support, including types and traits for...
CVE-2026-22688HIGH8.8WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0....
CVE-2026-22589HIGH7.5Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5,...
CVE-2026-22596HIGH7.2Ghost is a Node.js content management system. In versions 5.90.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerabili...
CVE-2026-22595HIGH8.1Ghost is a Node.js content management system. In versions 5.121.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerabil...
CVE-2026-22594HIGH8.1Ghost is a Node.js content management system. In versions 5.105.0 through 5.130.5 and 6.0.0 through 6.10.3, a vulnerabil...
CVE-2026-21884HIGH8.2React Router is a router for React. In @remix-run/react version prior to 2.17.3. and react-router 7.0.0 through 7.11.0, ...
CVE-2026-22612HIGH7.8Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, Fickling is vulnerable to detectio...
CVE-2026-22609HIGH7.8Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, the unsafe_imports() method in Fic...
CVE-2026-22608HIGH7.8Fickling is a Python pickling decompiler and static analyzer. Prior to version 0.1.7, both ctypes and pydoc modules aren...
CVE-2026-22607HIGH7.8Fickling is a Python pickling decompiler and static analyzer. Fickling versions up to and including 0.1.6 do not treat P...
CVE-2026-22606HIGH7.8Fickling is a Python pickling decompiler and static analyzer. Fickling versions up to and including 0.1.6 do not treat P...
CVE-2026-22601HIGH7.2OpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a regist...
CVE-2026-22697HIGH7.5CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2026-22026HIGH7.5CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2026-22023HIGH7.5CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2026-21898HIGH8.2CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2026-21897HIGH7.3CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2026-0830HIGH8.4Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge...
CVE-2026-22197HIGH8.1GestSup versions prior to 3.2.60 contain multiple SQL injection vulnerabilities in the asset list functionality. Multipl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now