2026 CVE Vulnerabilities

57,072 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-37270CRITICAL9.8Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper passwor...
CVE-2026-36163MEDIUM5.4An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execut...
CVE-2026-36162MEDIUM5.4An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 all...
CVE-2026-14895HIGH7.5String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtri...
CVE-2026-14740CRITICAL9.1DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The pr...
CVE-2026-14739CRITICAL9.8DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeho...
CVE-2026-14380HIGH8.8DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is ass...
CVE-2026-59706CRITICAL9.3mem0 contains unauthenticated config API endpoints that expose LLM API keys in plaintext and allow server-side request f...
CVE-2026-59153LOW2.1Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve me...
CVE-2026-58266MEDIUM6.5Anki is a program for creating and reviewing flashcards. Prior to 25.09.4, Anki's webview-based pages communicate with t...
CVE-2026-55490MEDIUM6.5OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a()...
CVE-2026-55418HIGH8.6FastGPT is an open source AI knowledge base platform. Prior to v4.15.0-beta5, two FastGPT file handlers authorize an unr...
CVE-2026-55408HIGH8.4Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution throu...
CVE-2026-55075HIGH7.4Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,...
CVE-2026-54698MEDIUM5.9Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a ...
CVE-2026-54607HIGH7.7FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta4, the HTTP-tool OpenAPI schema importer valid...
CVE-2026-54602HIGH7.1FastGPT is a knowledge-based AI application platform. Prior to 4.15.0, GET /api/core/ai/record/getRecord authenticates t...
CVE-2026-54601MEDIUM6.3FastGPT is an open source AI knowledge base platform. From 4.14.17 to before 4.15.0-beta4, FastGPT allows an authenticat...
CVE-2026-50179MEDIUM4.2Actual is a local-first personal finance tool. Prior to 26.6.0, exportToCSV and exportQueryToCSV in packages/loot-core/s...
CVE-2026-49229HIGH8.3Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks f...
CVE-2026-49033HIGH8.4The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arb...
CVE-2026-46354CRITICAL9.1Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29...
CVE-2026-45796MEDIUM6.5Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13...
CVE-2026-42958HIGH8.4The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing s...
CVE-2026-42953HIGH8.4The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now