2026 CVE Vulnerabilities

57,083 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-58402MEDIUM5.4Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-f...
CVE-2026-55646MEDIUM6.5vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions a...
CVE-2026-53763LOW3.8OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-50134MEDIUM5.8Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL i...
CVE-2026-50133MEDIUM6.1Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to...
CVE-2026-44362MEDIUM5.5OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-42546LOW3.8OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-41516LOW3.3OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-41515LOW3.3OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-41514LOW3.3OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-14898MEDIUM6.5The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could pl...
CVE-2026-14536HIGH8.8Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attack...
CVE-2026-11405CRITICAL9.8The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8...
CVE-2026-9182CRITICAL9.8Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this is...
CVE-2026-9181HIGH7.5Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An una...
CVE-2026-55798MEDIUM4.5Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by ...
CVE-2026-55380HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from t...
CVE-2026-55379HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field f...
CVE-2026-54291MEDIUM5.9pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections ...
CVE-2026-54060HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into ...
CVE-2026-54059HIGH7.5Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the P...
CVE-2026-13753HIGH7.5Certain HP DeskJet All-in-One printers may be potentially vulnerable to information disclosure that allows an unauthenti...
CVE-2026-48614CRITICAL9.9An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configurat...
CVE-2026-41434LOW3.3OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-12154MEDIUM6.4The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now