2026 CVE Vulnerabilities

57,072 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28378LOW2.7The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organizatio...
CVE-2026-59707CRITICAL9.2LocalAI contains an unauthenticated server-side request forgery vulnerability in the POST /models/apply endpoint that al...
CVE-2026-58583HIGH8.4FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege esc...
CVE-2026-58473CRITICAL9.3Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite...
CVE-2026-58472HIGH7.1GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string...
CVE-2026-58471HIGH7.1GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() f...
CVE-2026-58470MEDIUM6.9GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range(...
CVE-2026-58469HIGH8.7GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_s...
CVE-2026-57172HIGH8.3DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, ShareSecretManage uses a hardcoded de...
CVE-2026-55647MEDIUM5.1DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, dashboard text components render stor...
CVE-2026-55635HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, chart quota and Y-axis filters embed ...
CVE-2026-55633HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and f...
CVE-2026-55631HIGH7.2DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the font management module allows aut...
CVE-2026-55592LOW3.9Dashy is a self-hostable personal dashboard. Prior to 4.3.7, Dashy's workspace view trusts the url query parameter and a...
CVE-2026-55434MEDIUM6.5Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and pr...
CVE-2026-55417MEDIUM6.9Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user ena...
CVE-2026-53935MEDIUM6.9Cilium is a networking, observability, and security solution. Prior to 1.17.16, from 1.18.2 to 1.18.9, and from 1.19.0 t...
CVE-2026-53751HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the H2 database JDBC URL validation l...
CVE-2026-53730HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/datasetData/previewSql en...
CVE-2026-53729HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, any authenticated user can download (...
CVE-2026-53511HIGH8.5calibre is an e-book manager. Prior to 9.10.0, a malicious EPUB, OPF, or PDF file can execute arbitrary Python code when...
CVE-2026-50530HIGH7.1DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a share mode chart data interface onl...
CVE-2026-50529HIGH8.7DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, the /de2api/share/proxyInfo share int...
CVE-2026-50007HIGH7.2Actual is an open-source personal finance application. Prior to 26.7.0, a missing authorization issue allows a shared us...
CVE-2026-49471HIGH8.3Serena is a powerful MCP toolkit for coding that provides semantic retrieval and editing capabilities. Prior to v1.5.2, ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now