2026 CVE Vulnerabilities

45,001 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-45793HIGH7.5Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConf...
CVE-2026-20187HIGH7.5As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c...
CVE-2026-20158HIGH7.5As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c...
CVE-2026-20153HIGH7.5As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c...
CVE-2026-20150HIGH8.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c...
CVE-2026-62685HIGH8.1File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-61828HIGH8.5Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and ...
CVE-2026-61371HIGH7.5Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/...
CVE-2026-60005HIGH8.2NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and ...
CVE-2026-55242HIGH8.8ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated use...
CVE-2026-50147HIGH7.6Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1....
CVE-2026-47164HIGH7.7Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the ...
CVE-2026-47158HIGH8.3Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did ...
CVE-2026-46709HIGH7.8Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths...
CVE-2026-45806HIGH7.7Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import pa...
CVE-2026-45805HIGH8.8Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/serve...
CVE-2026-61836HIGH8.6Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching ...
CVE-2026-61835HIGH7.7Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on...
CVE-2026-61684HIGH8.8FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints unde...
CVE-2026-61644HIGH7.7FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api/core/chat/record/ge...
CVE-2026-61613HIGH7.7Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Curso...
CVE-2026-59762HIGH8.7When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource ...
CVE-2026-56434HIGH8.3NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist wh...
CVE-2026-55723HIGH8.7When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection...
CVE-2026-54563HIGH7.1Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now