2026 CVE Vulnerabilities

60,200 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54012HIGH7.1Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ...
CVE-2026-54011MEDIUM5.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6,Open W...
CVE-2026-54010HIGH8.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ...
CVE-2026-54009MEDIUM6.5Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST ...
CVE-2026-54008HIGH8.5Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backe...
CVE-2026-54007MEDIUM6.5Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the c...
CVE-2026-54006MEDIUM4.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST ...
CVE-2026-53662CRITICAL9.6immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a refl...
CVE-2026-52846MEDIUM4.2Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function ca...
CVE-2026-52845HIGH8.1Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the ...
CVE-2026-52844HIGH7.5Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat ...
CVE-2026-50221MEDIUM5.4In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Dev...
CVE-2026-49983MEDIUM5.2Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permis...
CVE-2026-49860MEDIUM5.2Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when a WebSocket connection was opened, Deno ...
CVE-2026-49859MEDIUM5.2Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when fetch() was called, Deno checked the des...
CVE-2026-49440HIGH7.4Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, node:crypto.checkPrime(candidate[, options][,...
CVE-2026-49411MEDIUM6.5Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.0, the Node.js compatibility TCP path checked th...
CVE-2026-49406MEDIUM5.5Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.12, when Deno was run in BYONM mode (nodeModules...
CVE-2026-49402HIGH8.1Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation pro...
CVE-2026-49401HIGH8.4Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.14, Deno's permission system enforces filesystem...
CVE-2026-45692LOW3.8Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and th...
CVE-2026-45135HIGH8.1Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitP...
CVE-2026-44726CRITICAL9.1Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatib...
CVE-2026-0864MEDIUM5.5When using the "configparser" module to write configuration files containing multi-line text values with carriage return...
CVE-2026-56968MEDIUM5.3GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now