2026 CVE Vulnerabilities

57,045 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54769CRITICAL10Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable ...
CVE-2026-54760CRITICAL9.3Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAge...
CVE-2026-50181HIGH7.1Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `Rea...
CVE-2026-50180HIGH8.7Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, `SQLChatAgent` ...
CVE-2026-15317MEDIUM6.3A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. Affected by this vulnerability is the function WebFe...
CVE-2026-15311LOW3.5A vulnerability was identified in NousResearch hermes-agent up to 2026.5.29.2. Affected by this issue is the function Ma...
CVE-2026-12598HIGH8.1The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via...
CVE-2026-12597HIGH8.1The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions...
CVE-2026-12595HIGH8.1The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all version...
CVE-2026-59858HIGH7.8Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/cco...
CVE-2026-59857MEDIUM5.5Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in s...
CVE-2026-59856HIGH7.8Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/p...
CVE-2026-59855HIGH8.6SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, Asset.render in app/src/asset/index.ts in...
CVE-2026-59854MEDIUM4.9SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, POST /api/file/globalCopyFiles accepts at...
CVE-2026-59853MEDIUM6.5SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /api/storage/getCriteria endpoint ret...
CVE-2026-59834HIGH7.5SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the block search endpoint POST /api/searc...
CVE-2026-59833HIGH8.6SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, SiYuan renders note and package content t...
CVE-2026-59832HIGH7.7SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler ser...
CVE-2026-59831MEDIUM4.4GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace ...
CVE-2026-57501NONE0Zen is a firefox-based browser. Prior to 1.21.5b, Zen's glance and split-view context-menu actions, Open link in glance ...
CVE-2026-44342MEDIUM5.3New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0...
CVE-2026-33655HIGH7.7New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0...
CVE-2026-59828MEDIUM5.3Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, post revisions tha...
CVE-2026-58144MEDIUM5.4Cotonti Siena 0.9.26 and earlier contains a stored cross-site scripting vulnerability that allows authenticated users wi...
CVE-2026-58143HIGH8.8Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated attacke...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now