2026 CVE Vulnerabilities

57,076 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41899MEDIUM6.5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-38979MEDIUM5.4ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/...
CVE-2026-38976HIGH7.5mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missi...
CVE-2026-38973MEDIUM4.4mrubyc through release3.4.1 was found to contain an out-of-bounds read in builtin missing-method lookup inside mrbc_find...
CVE-2026-34599HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34167MEDIUM5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34153HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34050MEDIUM6.5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34049LOW3.3Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.451 ...
CVE-2026-32718MEDIUM6.5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-59713HIGH8.6Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without...
CVE-2026-59712HIGH8.6Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to ...
CVE-2026-59711MEDIUM6.1showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitr...
CVE-2026-57573HIGH8.6Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF ...
CVE-2026-57572CRITICAL10Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-...
CVE-2026-57571CRITICAL9.6Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded fil...
CVE-2026-55727HIGH7.5A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14...
CVE-2026-55574HIGH7.5vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_ou...
CVE-2026-55514MEDIUM6.5vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a...
CVE-2026-54765HIGH8.5Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gatewa...
CVE-2026-54764MEDIUM5.8Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middle...
CVE-2026-54763CRITICAL10Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestA...
CVE-2026-54709Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-54637. Reason: This candidate is a ...
CVE-2026-54234HIGH7.5vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal ...
CVE-2026-50135MEDIUM5.5Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made  RootMappingFs.statRoot  use  Stat  (follows...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now