2026 CVE Vulnerabilities

58,076 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-59100MEDIUM5LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to...
CVE-2026-59099CRITICAL9.3Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to...
CVE-2026-59098HIGH7.1LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic sea...
CVE-2026-59097MEDIUM6.9Taiga before 6.10.2 contains a missing authorization vulnerability that allows unauthenticated remote attackers to creat...
CVE-2026-59096HIGH8.2Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-configuration document ...
CVE-2026-59095HIGH8.3LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attacker...
CVE-2026-59094HIGH8.7Pathway through 0.31.1, fixed in commit d09722e, document store applies a caller-supplied glob pattern to indexed docume...
CVE-2026-59093HIGH8.8Weaviate before 1.38.0 does not verify that a principal performing an RBAC role assignment holds the permissions granted...
CVE-2026-59092CRITICAL9.8JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthentica...
CVE-2026-58580MEDIUM6LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. ...
CVE-2026-58579MEDIUM5.4RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalize...
CVE-2026-58578HIGH7.1LobeChat before version 2.2.10-canary.15 contains a regular expression denial of service (ReDoS) vulnerability that allo...
CVE-2026-58467HIGH8.2Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated ...
CVE-2026-58466CRITICAL9.8AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers t...
CVE-2026-58381MEDIUM6.1A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function whe...
CVE-2026-52187HIGH7.5Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of s...
CVE-2026-7311HIGH8.1The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to in...
CVE-2026-58465HIGH8.7Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 hand...
CVE-2026-13743LOW3.3CubeSpace CW0057 Reaction Wheel firmware versions prior to 5.0.20 are vulnerable to an Improper Verification of Cryptogr...
CVE-2026-8699HIGH7A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5...
CVE-2026-55952HIGH7.5The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientH...
CVE-2026-55950MEDIUM5.9Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an u...
CVE-2026-54891LOW3.7Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Erlang/OTP ssl...
CVE-2026-54887MEDIUM4.8Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DTLS cookie computatio...
CVE-2026-54886MEDIUM4.3Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an auth...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now