2026 CVE Vulnerabilities

61,122 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48979HIGH7.5PHP Standard Library (PSL) is set of APIs covering async, collections, networking, I/O, cryptography, terminal UI, etc. ...
CVE-2026-48821MEDIUM5.8Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vuln...
CVE-2026-55202HIGH8.8Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection,...
CVE-2026-55201HIGH7.4Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function ...
CVE-2026-55200HIGH8.3libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() t...
CVE-2026-55199HIGH7.5libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SS...
CVE-2026-54388CRITICAL9.3Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers w...
CVE-2026-54387CRITICAL9.3Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: ...
CVE-2026-50107HIGH8.6When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerabilit...
CVE-2026-48823MEDIUM4.8Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnera...
CVE-2026-48822MEDIUM5.8Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnera...
CVE-2026-48817MEDIUM5.3Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint...
CVE-2026-48814CRITICAL9.1Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows un...
CVE-2026-32682HIGH7.1When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or...
CVE-2026-12529HIGH7.3A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1...
CVE-2026-11407HIGH8.6Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attacker...
CVE-2026-10741MEDIUM4.9Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configur...
CVE-2026-10696HIGH7.5Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier all...
CVE-2026-55198MEDIUM6.5Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows a...
CVE-2026-55197MEDIUM6.5Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows aut...
CVE-2026-55196CRITICAL9.1Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allo...
CVE-2026-53871HIGH8.1Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that ac...
CVE-2026-53870MEDIUM6.8Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mod...
CVE-2026-53869HIGH8.7Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to...
CVE-2026-48818HIGH7.5Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now