2026 CVE Vulnerabilities
57,052 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43752 | MEDIUM | 4.9 | 0.3% | Jul 9, 2026 | An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicio... |
| CVE-2026-15204 | MEDIUM | 5.5 | 0.5% | Jul 9, 2026 | A vulnerability was detected in TOTOLINK X5000R 9.1.0cu.2415_B20250515/9.1.0cu.2350_B20230313. Affected by this vulnerab... |
| CVE-2026-15202 | MEDIUM | 4.3 | — | Jul 9, 2026 | A security vulnerability has been detected in YzmCMS up to 7.5. Affected is the function get_url of the file /yzmphp/yzm... |
| CVE-2026-15195 | MEDIUM | 6.3 | — | Jul 9, 2026 | A weakness has been identified in apidevtools json-schema-ref-parser up to 15.3.5. This impacts the function Refs.set/Po... |
| CVE-2026-14278 | — | — | — | Jul 9, 2026 | Rejected reason: After further coordination, CVE was determined to not be warranted. |
| CVE-2026-59715 | MEDIUM | 6.5 | — | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.16 before 0.10.0, the Soc... |
| CVE-2026-59227 | MEDIUM | 5.4 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /a... |
| CVE-2026-59226 | MEDIUM | 4.3 | — | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_... |
| CVE-2026-59225 | MEDIUM | 6.3 | — | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.12 before 0.10.0, an auth... |
| CVE-2026-59224 | HIGH | 8 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webu... |
| CVE-2026-59223 | MEDIUM | 4.3 | 0.2% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, WEB_FETCH_FILTER_... |
| CVE-2026-59222 | MEDIUM | 6.5 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 before 0.10.0, GET /api... |
| CVE-2026-59220 | MEDIUM | 6.5 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.2 before 0.10.0, the SKIL... |
| CVE-2026-59219 | HIGH | 7.1 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0 with Redi... |
| CVE-2026-59218 | MEDIUM | 5.3 | 0.2% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the /api/v1/auths... |
| CVE-2026-59217 | MEDIUM | 4.3 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the file upload p... |
| CVE-2026-59216 | CRITICAL | 9 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call de... |
| CVE-2026-59215 | LOW | 3.1 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread pa... |
| CVE-2026-59214 | CRITICAL | 9 | 0.2% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs c... |
| CVE-2026-59213 | MEDIUM | 5 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all... |
| CVE-2026-59212 | MEDIUM | 5.4 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _verify_... |
| CVE-2026-59209 | MEDIUM | 6.5 | 0.3% | Jul 9, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with... |
| CVE-2026-58459 | CRITICAL | 9.6 | 1.8% | Jul 9, 2026 | gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows ... |
| CVE-2026-53987 | HIGH | 7.3 | 0.3% | Jul 9, 2026 | The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sanitization and renders it into the Kanban ba... |
| CVE-2026-51606 | HIGH | 7.5 | 0.3% | Jul 9, 2026 | An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now