2026 CVE Vulnerabilities

63,579 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-42951MEDIUM5.9An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes accoun...
CVE-2026-42941HIGH8.7The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password c...
CVE-2026-42929HIGH8.7Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.
CVE-2026-40425MEDIUM4.9The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive file...
CVE-2026-7786CRITICAL9.8Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintex...
CVE-2026-6824HIGH8.4A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitiza...
CVE-2026-5768HIGH8.8The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing p...
CVE-2026-5386CRITICAL9.1The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an ...
CVE-2026-47179HIGH7.7Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.Ge...
CVE-2026-47125HIGH8.8Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/envi...
CVE-2026-45668CRITICAL9.3Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bas...
CVE-2026-45661CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerab...
CVE-2026-45660MEDIUM5.4Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.22 and 6.18.1, the Glide image prox...
CVE-2026-45633CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injecti...
CVE-2026-45632CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enfor...
CVE-2026-45631CRITICAL10Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.27.0 to before 0.29.3, a hardcoded BETTER_AUTH_SEC...
CVE-2026-45630CRITICAL9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection...
CVE-2026-45629CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection...
CVE-2026-45628CRITICAL9.6Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands ...
CVE-2026-45627HIGH8.2Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticat...
CVE-2026-45626MEDIUM6.3Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /enviro...
CVE-2026-45625CRITICAL9.9Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-bas...
CVE-2026-45577MEDIUM6.9Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public...
CVE-2026-44697HIGH8.6Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-...
CVE-2026-43917MEDIUM5.3Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.19.0 and earlier, the protectedProcedure middleware ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now