2026 CVE Vulnerabilities

61,772 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41412MEDIUM4.9alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio...
CVE-2026-40108HIGH7.1GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XS...
CVE-2026-35482CRITICAL9.1alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio...
CVE-2026-32625CRITICAL9.6LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the M...
CVE-2026-31942HIGH7.1LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an In...
CVE-2026-27145MEDIUM6.5(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN...
CVE-2026-25861HIGH8.2QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attack...
CVE-2026-10719LOW1.8Out of bounds write in openSeaChest’s --showSupportedFormats in Seagate’s openSeaChest v25.05.3 on all supported platfor...
CVE-2026-10718MEDIUM4.6Out of bounds write in openSeaChest’s Trim/Unmap operation in Seagate’s openSeaChest v26.03.0 on all supported platforms...
CVE-2026-10717LOW1.8Out of bounds write and reads in openSeaChest’s --showSCSIDefects in Seagate’s openSeaChest v25.05.3 on all supported pl...
CVE-2026-10688MEDIUM5.5A vulnerability was determined in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The impacted elem...
CVE-2026-10662MEDIUM6.3A vulnerability was found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The affected element i...
CVE-2026-8936HIGH8.2Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested dire...
CVE-2026-42029Rejected reason: This CVE is a duplicate of another CVE.
CVE-2026-35212MEDIUM6.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7...
CVE-2026-10661MEDIUM4.3A vulnerability has been found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. Impacted is the f...
CVE-2026-10650MEDIUM5.5A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of t...
CVE-2026-49448CRITICAL9.8authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can...
CVE-2026-49443HIGH8.8authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the...
CVE-2026-49144HIGH7.1BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js ...
CVE-2026-49143HIGH8.8BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows u...
CVE-2026-47201HIGH8.5authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Sou...
CVE-2026-45289MEDIUM5.3CloudburstMC Protocol is a protocol library for Minecraft Bedrock Edition. Prior to version 3.0.0.Beta12-20260420.182526...
CVE-2026-42849CRITICAL9.3authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of st...
CVE-2026-41569MEDIUM6.1authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now