2026 CVE Vulnerabilities

44,998 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-46485HIGH8.2Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated user...
CVE-2026-15895HIGH8.4OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent ...
CVE-2026-12997HIGH7.5The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4...
CVE-2026-59258HIGH8.3immich before 3.0.3 contains a broken access control vulnerability in the PUT /albums/:id/user/:userId endpoint that all...
CVE-2026-59255HIGH7.1BloodHound through 9.4.0, fixed in commit 8f79035, contains a missing authorization vulnerability in the custom-nodes AP...
CVE-2026-58660HIGH8.1Kanboard through 1.2.52, fixed in commit 564cc30, BoardAjaxController save() method (used by the kanban board drag-and-d...
CVE-2026-58659HIGH8.4PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_st...
CVE-2026-58658HIGH8.8GPUStack through 2.2.1, fixed in commit 4e20551, contains an unauthenticated information disclosure vulnerability that a...
CVE-2026-56687HIGH7.8Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Feature in UI vulnerability. A low privileged attack...
CVE-2026-53518HIGH8.1Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oau...
CVE-2026-53517HIGH8.1Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-a...
CVE-2026-53516HIGH8.3Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, Better Auth's OAuth callback...
CVE-2026-53515HIGH7.1Better Auth is an authentication and authorization library for TypeScript. From 1.2.10 until 1.6.11, the @better-auth/ss...
CVE-2026-53514HIGH7.7Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, and in 1.6.14 and later when...
CVE-2026-45337HIGH7.6Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the deviceAuthorizat...
CVE-2026-40501HIGH8.8Cherry Studio versions 1.2.2 through 1.9.12, fixed in commit 1518530, contain a remote code execution vulnerability in S...
CVE-2026-20297HIGH7.2In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below...
CVE-2026-20296HIGH8.3In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.26...
CVE-2026-12382HIGH8.2A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove t...
CVE-2026-10673HIGH8.3The Zephyr ADIN2111/ADIN1110 10BASE-T1S/T1L Ethernet driver (drivers/ethernet/eth_adin2111.c) reassembles received Ether...
CVE-2026-59955HIGH7.5Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior...
CVE-2026-59954HIGH7.5Apollo is a reliable configuration management system suitable for microservice configuration management scenarios. Prior...
CVE-2026-48799HIGH7.7Postiz is an AI social media scheduling tool. Prior to 2.21.8, Postiz fails to verify Nowpayments IPN callback authentic...
CVE-2026-45804HIGH7.5Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretraine...
CVE-2026-45793HIGH7.5Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConf...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now