2026 CVE Vulnerabilities

62,186 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44652MEDIUM6.9SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-44651MEDIUM6.9SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-44650CRITICAL9.1SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-44649CRITICAL9.8SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-44648HIGH7.5SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode...
CVE-2026-44611MEDIUM5.9Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is su...
CVE-2026-44518MEDIUM5.3liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prio...
CVE-2026-42951MEDIUM5.9An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes accoun...
CVE-2026-42941HIGH8.7The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password c...
CVE-2026-42929HIGH8.7Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.
CVE-2026-40425MEDIUM4.9The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive file...
CVE-2026-7786CRITICAL9.8Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintex...
CVE-2026-6824HIGH8.4A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitiza...
CVE-2026-5768HIGH8.8The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing p...
CVE-2026-5386CRITICAL9.1The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an ...
CVE-2026-47179HIGH7.7Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.Ge...
CVE-2026-47125HIGH8.8Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/envi...
CVE-2026-45668CRITICAL9.3Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas...
CVE-2026-45661CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerab...
CVE-2026-45660MEDIUM5.4Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image prox...
CVE-2026-45633CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injecti...
CVE-2026-45632CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enfor...
CVE-2026-45631CRITICAL10Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SEC...
CVE-2026-45630CRITICAL9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection...
CVE-2026-45629CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now