2026 CVE Vulnerabilities

57,072 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-59998MEDIUM6.5sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if th...
CVE-2026-59997MEDIUM5.4internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important ...
CVE-2026-59996MEDIUM5.4scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs betwee...
CVE-2026-59995MEDIUM5.4sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is u...
CVE-2026-56843CRITICAL9.9Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated custo...
CVE-2026-55438MEDIUM6.8Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7...
CVE-2026-55437MEDIUM5.4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7...
CVE-2026-55436HIGH7.4Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and pr...
CVE-2026-55433MEDIUM5.4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55432MEDIUM5.4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55431MEDIUM6.1Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55430MEDIUM6.8Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55429HIGH8.7Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55428HIGH8.2Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55427HIGH8.3Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55079MEDIUM6.5Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and pr...
CVE-2026-59705CRITICAL9.8mem0's openmemory/api component contains an unauthenticated access vulnerability that allows unauthenticated attackers t...
CVE-2026-59704HIGH7.1Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metada...
CVE-2026-55078MEDIUM6.5Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and pr...
CVE-2026-55077HIGH7.2Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-55076HIGH7.4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-51937HIGH7.5An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsAp...
CVE-2026-50811MEDIUM6.5An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736...
CVE-2026-50810MEDIUM5.5A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35...
CVE-2026-37271CRITICAL9.8Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GA...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now