2026 CVE Vulnerabilities

64,369 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45310HIGH7.4CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validates the initial URL's...
CVE-2026-45307MEDIUM6.1Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.20-alpha, the...
CVE-2026-45306MEDIUM6.5pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509...
CVE-2026-45297MEDIUM5.3OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assi...
CVE-2026-45296HIGH7.7OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's Python API exposes several app_apikey ro...
CVE-2026-45058CRITICAL9.4electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is...
CVE-2026-45021MEDIUM5.1Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.25, 2...
CVE-2026-44798HIGH7.1Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to ...
CVE-2026-44797HIGH8.5Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook dat...
CVE-2026-44796MEDIUM6.5Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bul...
CVE-2026-44794MEDIUM5.4Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, in the case of inter-o...
CVE-2026-43898CRITICAL10SandboxJS is a JavaScript sandboxing library. Prior to 0.9.6, sandbox-defined functions expose Function.caller, allowing...
CVE-2026-34126HIGH7.5TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth...
CVE-2026-9098CRITICAL9.1In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLRe...
CVE-2026-9097CRITICAL9.8Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExcha...
CVE-2026-9096HIGH7.5Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-val...
CVE-2026-9095HIGH8.1Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlRespon...
CVE-2026-9094CRITICAL9.8Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExc...
CVE-2026-9093CRITICAL9.8In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestrict...
CVE-2026-9092CRITICAL9.1Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account ...
CVE-2026-9091MEDIUM5.3Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass c...
CVE-2026-9090CRITICAL9.1Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplyi...
CVE-2026-8697HIGH8.8Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service all...
CVE-2026-6720HIGH7.2When calicoctl is invoked with --log-level=info or --log-level=debug, the client prints the full contents of its loaded ...
CVE-2026-47676MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.21, app.mount() stri...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now