2026 CVE Vulnerabilities

60,151 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54069CRITICAL9.2SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan Note's kernel HTTP server uncondit...
CVE-2026-54068MEDIUM5.9SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is ...
CVE-2026-54067CRITICAL9.9SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> brea...
CVE-2026-54066HIGH7.5SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Trave...
CVE-2026-53766MEDIUM6.1Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From ...
CVE-2026-53765MEDIUM6.1Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From ...
CVE-2026-52794HIGH7.5Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Se...
CVE-2026-50551CRITICAL9.9SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scrip...
CVE-2026-50189HIGH7.2Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, Appsmith's bundled superviso...
CVE-2026-49979LOW2.7Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send...
CVE-2026-47110HIGH7.1Tiptap for PHP before version 2.1.1 contains an input validation vulnerability that allows authenticated attackers to ca...
CVE-2026-47093Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-39897MEDIUM6.1Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vu...
CVE-2026-39894LOW2.5Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent d...
CVE-2026-39893CRITICAL9.8Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request va...
CVE-2026-2050HIGH7.8GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2026-10642MEDIUM4.6The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx_enable() ...
CVE-2026-10043HIGH7.8MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remot...
CVE-2026-7539HIGH7.3A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking St...
CVE-2026-52816MEDIUM5.4Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Jupyter Notebook (ipynb) sanitizer endpoint at POST...
CVE-2026-52815MEDIUM5.5Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vuln...
CVE-2026-52814MEDIUM5.5Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs built-in Go SSH server is vulnerable to an una...
CVE-2026-52813CRITICAL10Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences ...
CVE-2026-52812HIGH7.1Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (<LFS...
CVE-2026-52811CRITICAL9Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now