2026 CVE Vulnerabilities

63,681 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48116HIGH8.8AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-47713MEDIUM4.3AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-45410MEDIUM5.3TREK is a collaborative travel planner. Prior to 3.0.18, early return on missing user during login flow allowed an attac...
CVE-2026-45403LOW2.5AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-45366MEDIUM4.7typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utcp/http package is vulnerable to a blind ...
CVE-2026-45364HIGH7.3Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth...
CVE-2026-45344HIGH8.1LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, the setup database configuration flow on unin...
CVE-2026-45343HIGH8.5LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains a stored cross-site scriptin...
CVE-2026-45342HIGH7.1LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains an Insecure Direct Object Re...
CVE-2026-45023MEDIUM5.4AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-44973HIGH8.1Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across differe...
CVE-2026-44885MEDIUM5.5Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-44884MEDIUM6.5Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-44883HIGH7.5Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-44882HIGH8.1Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-44881CRITICAL9.9Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-44850HIGH8.5Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-44849HIGH8.8Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-44848HIGH8.8Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-39929HIGH8.7Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulne...
CVE-2026-10044HIGH8.2Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{file...
CVE-2026-9646MEDIUM6.1A reflected cross-site scripting issue exists in URL handling.
CVE-2026-9645CRITICAL9.9Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts exe...
CVE-2026-49095MEDIUM6.5Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation....
CVE-2026-49094MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now