2026 CVE Vulnerabilities

60,200 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-46549LOW2NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauth_s...
CVE-2026-46548MEDIUM4.3NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the request-filtering-agent SSRF protecti...
CVE-2026-46547MEDIUM6.1NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, a reflected XSS vulnerability exists in t...
CVE-2026-41862HIGH8.8Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-ma...
CVE-2026-23513HIGH7.1FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-constructi...
CVE-2026-12892MEDIUM4.4A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing...
CVE-2026-12891MEDIUM4.3A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a cra...
CVE-2026-12112HIGH7.8A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated ...
CVE-2026-11820MEDIUM6.5A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the ...
CVE-2026-11819MEDIUM5.5Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module...
CVE-2026-11807CRITICAL9.6A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible...
CVE-2026-54762HIGH8.6Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerabilit...
CVE-2026-54761HIGH7.1Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in...
CVE-2026-54555HIGH7.8rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter ...
CVE-2026-54328HIGH7.3Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension packa...
CVE-2026-54327LOW2.2Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi stored API keys and OAuth credentials in auth.json...
CVE-2026-54326LOW2.5Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi HTML exports render session Markdown into a static...
CVE-2026-54325MEDIUM4.4Pi is a minimal terminal coding harness. Pi before 0.79.0 loaded project-local configuration and resources from a reposi...
CVE-2026-53622CRITICAL10Traefik is an HTTP reverse proxy and load balancer. Versions prior to 3.7.3, 3.6.18, and 2.11.51 have a critical vulnera...
CVE-2026-48491CRITICAL10Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Tr...
CVE-2026-48020CRITICAL10Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulner...
CVE-2026-45792MEDIUM5.5rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.32.0, RTK (Rust Token Killer) ...
CVE-2026-39253HIGH8.1An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll a...
CVE-2026-55736MEDIUM5.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a...
CVE-2026-55249HIGH8.8@rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now