2026 CVE Vulnerabilities

64,366 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49129MEDIUM6.9Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin...
CVE-2026-49128HIGH8.7Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrThrow a...
CVE-2026-49127HIGH8.8Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be f...
CVE-2026-42401MEDIUM5.4Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user...
CVE-2026-33590HIGH8.5Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access a...
CVE-2026-33464MEDIUM6.5Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-13...
CVE-2026-33463MEDIUM5.3Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclos...
CVE-2026-33462HIGH7.3A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with...
CVE-2026-32847HIGH8.7DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/mai...
CVE-2026-4944HIGH8.8vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in t...
CVE-2026-47337LOW3.3Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET...
CVE-2026-47336LOW3.3Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 so...
CVE-2026-47335MEDIUM5.5Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notificatio...
CVE-2026-47334MEDIUM5.5Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notifi...
CVE-2026-47333HIGH7.8Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an i...
CVE-2026-47332MEDIUM5.5Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structu...
CVE-2026-47331HIGH7.8Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivile...
CVE-2026-47330LOW3.3Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitializ...
CVE-2026-47329LOW3.3Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor n...
CVE-2026-47328MEDIUM6.1Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not ...
CVE-2026-47327LOW3.3Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmo...
CVE-2026-47326MEDIUM5.5Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor not...
CVE-2026-47136MEDIUM6.9RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rus...
CVE-2026-46685MEDIUM6RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS_ALLOWED_ORIGINS is ...
CVE-2026-46526MEDIUM5Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now