2026 CVE Vulnerabilities

61,069 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56022MEDIUM6.9Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, a...
CVE-2026-56021MEDIUM6.9Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due ...
CVE-2026-56020CRITICAL9.2The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL clie...
CVE-2026-55237HIGH8.8AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-55205MEDIUM5.3Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oa...
CVE-2026-55204HIGH8.7HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert()...
CVE-2026-55203CRITICAL9.1HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's ...
CVE-2026-54106MEDIUM5.1The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac...
CVE-2026-54105MEDIUM6.9The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac...
CVE-2026-54104HIGH8.8The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac...
CVE-2026-54103CRITICAL9.8The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac...
CVE-2026-48617HIGH8.2A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This...
CVE-2026-38718HIGH7.5InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a bu...
CVE-2026-38717CRITICAL9.8InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co...
CVE-2026-38716CRITICAL9.8InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co...
CVE-2026-38715CRITICAL9.8InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co...
CVE-2026-38714CRITICAL9.8InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co...
CVE-2026-11982MEDIUM5.1Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages A...
CVE-2026-10687Rejected reason: This CVE Record has been rejected by the Zephyr Project CNA. Subsequent analysis, confirmed with the fi...
CVE-2026-46580HIGH8.8In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were auto...
CVE-2026-44691HIGH8.8In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/t...
CVE-2026-44688HIGH8.8In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its...
CVE-2026-22551MEDIUM6.5In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP r...
CVE-2026-11791MEDIUM5A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees...
CVE-2026-9158CRITICAL9.8In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interfac...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now