2026 CVE Vulnerabilities

64,300 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45344HIGH8.1LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, the setup database configuration flow on unin...
CVE-2026-45343HIGH8.5LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains a stored cross-site scriptin...
CVE-2026-45342HIGH7.1LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains an Insecure Direct Object Re...
CVE-2026-45023MEDIUM5.4AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-44973HIGH8.1Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across differe...
CVE-2026-44885MEDIUM5.5Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-44884MEDIUM6.5Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-44883HIGH7.5Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-44882HIGH8.1Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-44881CRITICAL9.9Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-44850HIGH8.5Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-44849HIGH8.8Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-44848HIGH8.8Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-39929HIGH8.7Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulne...
CVE-2026-10044HIGH8.2Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{file...
CVE-2026-9646MEDIUM6.1A reflected cross-site scripting issue exists in URL handling.
CVE-2026-9645CRITICAL9.9Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts exe...
CVE-2026-49095MEDIUM6.5Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation....
CVE-2026-49094MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130)...
CVE-2026-49093HIGH7.7Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to ...
CVE-2026-46843MEDIUM5.3Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. E...
CVE-2026-46842MEDIUM5.3Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. E...
CVE-2026-46841MEDIUM5.3Vulnerability in Oracle REST Data Services (component: General). Supported versions that are affected are 24.2.0-26.1.0...
CVE-2026-46840CRITICAL10Vulnerability in Oracle REST Data Services (component: Backend-as-a-Service). Supported versions that are affected are ...
CVE-2026-46839CRITICAL9.9Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. E...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now