2026 CVE Vulnerabilities

64,755 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44562MEDIUM6.5Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the P...
CVE-2026-44561MEDIUM5.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the i...
CVE-2026-44560MEDIUM6.5Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the t...
CVE-2026-44559MEDIUM4.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the G...
CVE-2026-44558MEDIUM5.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the c...
CVE-2026-44557MEDIUM4.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the _...
CVE-2026-44556HIGH7.1Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /...
CVE-2026-44555HIGH7.6Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open ...
CVE-2026-44554HIGH8.1Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the P...
CVE-2026-44553HIGH8.1Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, admin...
CVE-2026-44552HIGH8.7Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the t...
CVE-2026-44551CRITICAL9.1Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the L...
CVE-2026-44550MEDIUM5Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Folde...
CVE-2026-8686CRITICAL9.1Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a den...
CVE-2026-4054MEDIUM6.5Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to validate the response body of proxie...
CVE-2026-4053MEDIUM4.3Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fiel...
CVE-2026-46408HIGH7.6Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3...
CVE-2026-46407HIGH8.1Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3...
CVE-2026-46367HIGH8.3phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in Utils::parseUrl() that allows authenticate...
CVE-2026-46366HIGH8.7phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that lacks pe...
CVE-2026-46365MEDIUM5.4phpMyFAQ before 4.1.2 contains a missing authorization vulnerability in the DELETE /admin/api/content/tags/{tagId} endpo...
CVE-2026-46364CRITICAL9.8phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and ...
CVE-2026-46363MEDIUM5.4phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that byp...
CVE-2026-46362HIGH7.1phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermiss...
CVE-2026-46361HIGH8.2phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and resu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now