2026 CVE Vulnerabilities

61,178 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48797CRITICAL9.3Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, th...
CVE-2026-48788HIGH8.2Remark42 is a self-hosted comment engine for blogs, articles, or any other place where readers can add comments. Version...
CVE-2026-48783MEDIUM4.8Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accept...
CVE-2026-48782MEDIUM6.8Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 t...
CVE-2026-48781CRITICAL9.9Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an atta...
CVE-2026-48779HIGH7.5ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, f...
CVE-2026-48745CRITICAL9.3Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Tracca...
CVE-2026-48616CRITICAL9.3Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in L...
CVE-2026-48055CRITICAL10Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior,...
CVE-2026-47340MEDIUM6.5Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. ...
CVE-2026-47277MEDIUM6.5Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos fro...
CVE-2026-45436MEDIUM6.5Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions.
CVE-2026-44587MEDIUM6.1CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_typ...
CVE-2026-42629HIGH8.8Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions.
CVE-2026-42385HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions.
CVE-2026-42380CRITICAL9.8Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.
CVE-2026-42357MEDIUM6.5Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do...
CVE-2026-41557HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Kapee < 1.7.1 versions.
CVE-2026-41280MEDIUM4.9Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthoriz...
CVE-2026-40783CRITICAL9.9Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.
CVE-2026-40768HIGH7.3Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 versions.
CVE-2026-40765HIGH7.1Unauthenticated Cross Site Scripting (XSS) in collectchat <= 2.4.9 versions.
CVE-2026-40761HIGH8.1Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
CVE-2026-40760HIGH8.1Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
CVE-2026-40759HIGH8.1Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now