2026 CVE Vulnerabilities

60,143 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-57231HIGH7.5Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environ...
CVE-2026-56823MEDIUM5.4AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-56663HIGH8.5AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-55686MEDIUM5.3Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where...
CVE-2026-55677HIGH7.5Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decodi...
CVE-2026-54636CRITICAL9.9Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system...
CVE-2026-48529MEDIUM6GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mo...
CVE-2026-45408CRITICAL9Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell meta...
CVE-2026-45407MEDIUM5.5Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:auth command creates $DOKKU_ROOT/.netrc using bash's touch comm...
CVE-2026-45406HIGH8.8Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-i...
CVE-2026-45405HIGH8.8Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/z...
CVE-2026-28385MEDIUM5In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import funct...
CVE-2026-13434MEDIUM4.9A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multu...
CVE-2026-11779MEDIUM5.3An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the ac...
CVE-2026-9640HIGH7.2A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 reg...
CVE-2026-9639MEDIUM6.5Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticat...
CVE-2026-5757HIGH7.5Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to ...
CVE-2026-47214HIGH7.1Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos...
CVE-2026-45195HIGH7.8Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memor...
CVE-2026-44018HIGH7.1Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos...
CVE-2026-21734HIGH7.7A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-...
CVE-2026-12411CRITICAL9.6Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, r...
CVE-2026-0828HIGH7.5Kernel driver ProcessMonitorDriver.sys in Safetica's endpoint client x64 , versions 10.5.75.0 and 11.11.4.0, allows unpr...
CVE-2026-0685CRITICAL9.8Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows...
CVE-2026-9699MEDIUM6.8Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now