2026 CVE Vulnerabilities

57,996 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-24690HIGH7.5Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
CVE-2026-24451HIGH7.5Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing ...
CVE-2026-22874CRITICAL9.6Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.
CVE-2026-22555HIGH8.1Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCrea...
CVE-2026-22547CRITICAL9.1Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited templa...
CVE-2026-20909MEDIUM5.3Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries.
CVE-2026-20896CRITICAL9.8Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any sour...
CVE-2026-20779HIGH7.1Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be ac...
CVE-2026-20706CRITICAL9.1Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web arc...
CVE-2026-14611MEDIUM5.3A vulnerability has been found in DeepMyst Mysti up to 0.4.0. The affected element is the function initProjectMemory of ...
CVE-2026-14610MEDIUM5.3A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::Int...
CVE-2026-14609MEDIUM5.6A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue...
CVE-2026-14355MEDIUM5.3In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algo...
CVE-2026-12481CRITICAL9.8A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deser...
CVE-2026-14608MEDIUM4.3A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1...
CVE-2026-14607MEDIUM5.5A weakness has been identified in RT-Thread up to 5.0.2. This affects the function sys_getaddrinfo of the file component...
CVE-2026-14606HIGH7.8A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function CAN_Receive in the ...
CVE-2026-14605HIGH7.8A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the l...
CVE-2026-58379HIGH7.3A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a rem...
CVE-2026-14604MEDIUM6.3A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporte...
CVE-2026-14631MEDIUM5.3webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends eit...
CVE-2026-14620MEDIUM4.7webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor a...
CVE-2026-14615LOW2.7A flaw was found in the Fine-Grained Admin Permissions (FGAP) v2 implementation within Keycloak's administrative service...
CVE-2026-14614MEDIUM5.4A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP)...
CVE-2026-14613MEDIUM4.9A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see informat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now