2026 CVE Vulnerabilities
60,149 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54037 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2025-710... |
| CVE-2026-54033 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users t... |
| CVE-2026-54030 | CRITICAL | 9.3 | 0.1% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implem... |
| CVE-2026-54029 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages... |
| CVE-2026-54027 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/imag... |
| CVE-2026-54025 | MEDIUM | 5.4 | 0.1% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, there is a vulnerability... |
| CVE-2026-54024 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2024-111... |
| CVE-2026-45233 | HIGH | 8.1 | 0.6% | Jun 25, 2026 | HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to re... |
| CVE-2026-13351 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a small num... |
| CVE-2026-13350 | LOW | 2.3 | 0.2% | Jun 25, 2026 | Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't b... |
| CVE-2026-9718 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-servi... |
| CVE-2026-9717 | HIGH | 7.2 | 1.0% | Jun 25, 2026 | CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could... |
| CVE-2026-9716 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the devi... |
| CVE-2026-9651 | MEDIUM | 4.4 | 0.1% | Jun 25, 2026 | CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of ... |
| CVE-2026-9650 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitiv... |
| CVE-2026-57456 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/pytho... |
| CVE-2026-57455 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in ... |
| CVE-2026-57454 | MEDIUM | 6.1 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. From 9.2.0320 until 9.2.0679, a crafted undo or swap file can store a v... |
| CVE-2026-57453 | HIGH | 7.3 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.... |
| CVE-2026-57452 | MEDIUM | 5.5 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04... |
| CVE-2026-57451 | MEDIUM | 6.1 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 pr... |
| CVE-2026-57438 | MEDIUM | 6.6 | 0.1% | Jun 25, 2026 | Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitutio... |
| CVE-2026-55895 | HIGH | 7.8 | 0.2% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s... |
| CVE-2026-55892 | MEDIUM | 5.5 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a ... |
| CVE-2026-55693 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c f... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now