2026 CVE Vulnerabilities
57,076 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41899 | MEDIUM | 6.5 | 0.3% | Jul 6, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-38979 | MEDIUM | 5.4 | 0.1% | Jul 6, 2026 | ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/... |
| CVE-2026-38976 | HIGH | 7.5 | 0.2% | Jul 6, 2026 | mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missi... |
| CVE-2026-38973 | MEDIUM | 4.4 | 0.2% | Jul 6, 2026 | mrubyc through release3.4.1 was found to contain an out-of-bounds read in builtin missing-method lookup inside mrbc_find... |
| CVE-2026-34599 | HIGH | 8.8 | 1.4% | Jul 6, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34167 | MEDIUM | 5 | 0.2% | Jul 6, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34153 | HIGH | 8.8 | 0.4% | Jul 6, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34050 | MEDIUM | 6.5 | 0.2% | Jul 6, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34049 | LOW | 3.3 | — | Jul 6, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.451 ... |
| CVE-2026-32718 | MEDIUM | 6.5 | 0.2% | Jul 6, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-59713 | HIGH | 8.6 | 0.2% | Jul 6, 2026 | Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without... |
| CVE-2026-59712 | HIGH | 8.6 | 0.3% | Jul 6, 2026 | Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to ... |
| CVE-2026-59711 | MEDIUM | 6.1 | 0.2% | Jul 6, 2026 | showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitr... |
| CVE-2026-57573 | HIGH | 8.6 | 0.3% | Jul 6, 2026 | Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF ... |
| CVE-2026-57572 | CRITICAL | 10 | 0.5% | Jul 6, 2026 | Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-... |
| CVE-2026-57571 | CRITICAL | 9.6 | 0.5% | Jul 6, 2026 | Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded fil... |
| CVE-2026-55727 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14... |
| CVE-2026-55574 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_ou... |
| CVE-2026-55514 | MEDIUM | 6.5 | 0.3% | Jul 6, 2026 | vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a... |
| CVE-2026-54765 | HIGH | 8.5 | 0.4% | Jul 6, 2026 | Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gatewa... |
| CVE-2026-54764 | MEDIUM | 5.8 | 0.4% | Jul 6, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middle... |
| CVE-2026-54763 | CRITICAL | 10 | 0.3% | Jul 6, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestA... |
| CVE-2026-54709 | — | — | — | Jul 6, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-54637. Reason: This candidate is a ... |
| CVE-2026-54234 | HIGH | 7.5 | 0.3% | Jul 6, 2026 | vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal ... |
| CVE-2026-50135 | MEDIUM | 5.5 | 0.4% | Jul 6, 2026 | Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made RootMappingFs.statRoot use Stat (follows... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now