2026 CVE Vulnerabilities

57,083 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-55514MEDIUM6.5vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a...
CVE-2026-54765HIGH8.5Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gatewa...
CVE-2026-54764MEDIUM5.8Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middle...
CVE-2026-54763CRITICAL10Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestA...
CVE-2026-54709Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-54637. Reason: This candidate is a ...
CVE-2026-54234HIGH7.5vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal ...
CVE-2026-50135MEDIUM5.5Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made  RootMappingFs.statRoot  use  Stat  (follows...
CVE-2026-48267MEDIUM5.5DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an...
CVE-2026-42341CRITICAL9.2FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenti...
CVE-2026-42331HIGH7.7FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/u...
CVE-2026-34038CRITICAL9.9Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-33734MEDIUM6.9FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injecti...
CVE-2026-25271HIGH7Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between chec...
CVE-2026-25268HIGH8.8Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
CVE-2026-21384MEDIUM5.3Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported ...
CVE-2026-21383HIGH7.1Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value fo...
CVE-2026-21379HIGH7.8Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
CVE-2026-21370MEDIUM5.3Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
CVE-2026-21369MEDIUM5.3Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
CVE-2026-21368MEDIUM5.3Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.
CVE-2026-14471HIGH8.6Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-g...
CVE-2026-14468HIGH7.7HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that...
CVE-2026-59089MEDIUM5.5A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calc...
CVE-2026-58404MEDIUM6.8Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests t...
CVE-2026-58403MEDIUM6.5Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files und...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now