2026 CVE Vulnerabilities

60,149 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54037MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2025-710...
CVE-2026-54033MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users t...
CVE-2026-54030CRITICAL9.3LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implem...
CVE-2026-54029MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages...
CVE-2026-54027MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/imag...
CVE-2026-54025MEDIUM5.4LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, there is a vulnerability...
CVE-2026-54024MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2024-111...
CVE-2026-45233HIGH8.1HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to re...
CVE-2026-13351HIGH7.5Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a small num...
CVE-2026-13350LOW2.3Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't b...
CVE-2026-9718MEDIUM6.5CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-servi...
CVE-2026-9717HIGH7.2CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could...
CVE-2026-9716HIGH7.5CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the devi...
CVE-2026-9651MEDIUM4.4CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of ...
CVE-2026-9650HIGH7.5CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitiv...
CVE-2026-57456HIGH7.8Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/pytho...
CVE-2026-57455HIGH7.8Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in ...
CVE-2026-57454MEDIUM6.1Vim is an open source, command line text editor. From 9.2.0320 until 9.2.0679, a crafted undo or swap file can store a v...
CVE-2026-57453HIGH7.3Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip....
CVE-2026-57452MEDIUM5.5Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04...
CVE-2026-57451MEDIUM6.1Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 pr...
CVE-2026-57438MEDIUM6.6Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitutio...
CVE-2026-55895HIGH7.8Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s...
CVE-2026-55892MEDIUM5.5Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a ...
CVE-2026-55693HIGH7.8Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c f...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now