2026 CVE Vulnerabilities

64,617 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-9580HIGH7.3A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepa...
CVE-2026-9579MEDIUM6.3A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/logi...
CVE-2026-8676HIGH8.8An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bo...
CVE-2026-48593MEDIUM5.9Uncontrolled Resource Consumption vulnerability in oban-bg oban_web ('Elixir.Oban.Web.CronExpr' modules) allows memory e...
CVE-2026-48592MEDIUM5.3Missing Authorization vulnerability in oban-bg oban_web ('Elixir.Oban.Web.Jobs.DetailComponent' modules) allows unauthor...
CVE-2026-47672MEDIUM6.5epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and earlier, any networ...
CVE-2026-45575HIGH7.4epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who ...
CVE-2026-45413MEDIUM6.9MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, user passwords are stored using unsalted MD5 hashes...
CVE-2026-45412MEDIUM6.3MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated u...
CVE-2026-44899MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the...
CVE-2026-44898MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-c...
CVE-2026-44897MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the openin...
CVE-2026-44896MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and earlier, in src/mistune/directives/image.py...
CVE-2026-44847HIGH7.5MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/w...
CVE-2026-44844MEDIUM6.3eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well...
CVE-2026-44843HIGH8.2LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains...
CVE-2026-44837HIGH7.5view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3...
CVE-2026-44836MEDIUM6.5view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3...
CVE-2026-44708MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plugin renders inline m...
CVE-2026-44451CRITICAL9.3Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied...
CVE-2026-44450CRITICAL9.9Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the MCP server creation endpoint validates the command...
CVE-2026-44449CRITICAL9.1Lumiverse is a full-featured AI chat application. Prior to 0.9.7, when the primary toSmbPath(fullPath) call throws, the ...
CVE-2026-44444CRITICAL9.1Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the Spindle extension build pipeline calls bun install...
CVE-2026-44443MEDIUM4.8Lumiverse is a full-featured AI chat application. Prior to 0.9.7, consumeNonce() only checks that the module-level varia...
CVE-2026-44209HIGH7.5Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Env...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now