2026 CVE Vulnerabilities

60,364 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-50107HIGH8.6When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerabilit...
CVE-2026-48823MEDIUM4.8Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnera...
CVE-2026-48822MEDIUM5.8Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnera...
CVE-2026-48817MEDIUM5.3Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint...
CVE-2026-48814CRITICAL9.1Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows un...
CVE-2026-32682HIGH7.1When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or...
CVE-2026-12529HIGH7.3A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1...
CVE-2026-11407HIGH8.6Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attacker...
CVE-2026-10741MEDIUM4.9Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configur...
CVE-2026-10696HIGH7.5Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier all...
CVE-2026-55198HIGH7.1Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows a...
CVE-2026-55197HIGH7.1Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows aut...
CVE-2026-55196CRITICAL9.1Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allo...
CVE-2026-53871HIGH8.6Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that ac...
CVE-2026-53870MEDIUM6.8Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mod...
CVE-2026-53869HIGH8.7Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to...
CVE-2026-48818HIGH7.5Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable t...
CVE-2026-9697HIGH7.4Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or s...
CVE-2026-9679MEDIUM5.9Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences...
CVE-2026-9678MEDIUM5.9Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control he...
CVE-2026-7300MEDIUM6.5Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web In...
CVE-2026-6734HIGH8.8Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying t...
CVE-2026-6733LOW3.7Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-con...
CVE-2026-53805CRITICAL9.8NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inf...
CVE-2026-48591MEDIUM4.8Improper Neutralization of Script in Attributes in a Web Page vulnerability in pragdave earmark allows stored cross-site...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now