2026 CVE Vulnerabilities

63,685 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45039CRITICAL9.8RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticate...
CVE-2026-44394HIGH8.1An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not p...
CVE-2026-43979MEDIUM5Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdo...
CVE-2026-43000HIGH8.8An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation ...
CVE-2026-42999HIGH8.8An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditi...
CVE-2026-42998HIGH8.8An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin d...
CVE-2026-30761HIGH7.3An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6...
CVE-2026-30760HIGH7.3An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the...
CVE-2026-46561MEDIUM5pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based p...
CVE-2026-45787CRITICAL9.1electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic ...
CVE-2026-45374CRITICAL9.6CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents...
CVE-2026-45373HIGH7.4CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, although SSRF is validated against hostnames t...
CVE-2026-45353HIGH7.8electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vul...
CVE-2026-45348HIGH8.7pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template a...
CVE-2026-45323CRITICAL9.6MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered witho...
CVE-2026-45311CRITICAL9.6CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in...
CVE-2026-45310HIGH7.4CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validates the initial URL's...
CVE-2026-45307MEDIUM6.1Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.20-alpha, the...
CVE-2026-45306MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509...
CVE-2026-45297MEDIUM5.3OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assi...
CVE-2026-45296HIGH7.7OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's Python API exposes several app_apikey ro...
CVE-2026-45058CRITICAL9.4electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is...
CVE-2026-45021MEDIUM5.1Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.25, 2...
CVE-2026-44798HIGH7.1Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to ...
CVE-2026-44797HIGH8.5Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook dat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now