2026 CVE Vulnerabilities
64,755 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44562 | MEDIUM | 6.5 | 0.3% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the P... |
| CVE-2026-44561 | MEDIUM | 5.4 | 0.2% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the i... |
| CVE-2026-44560 | MEDIUM | 6.5 | 0.4% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the t... |
| CVE-2026-44559 | MEDIUM | 4.3 | 0.2% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the G... |
| CVE-2026-44558 | MEDIUM | 5.4 | 0.2% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the c... |
| CVE-2026-44557 | MEDIUM | 4.3 | 0.2% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the _... |
| CVE-2026-44556 | HIGH | 7.1 | 0.3% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /... |
| CVE-2026-44555 | HIGH | 7.6 | 0.2% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open ... |
| CVE-2026-44554 | HIGH | 8.1 | 0.3% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the P... |
| CVE-2026-44553 | HIGH | 8.1 | 0.3% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, admin... |
| CVE-2026-44552 | HIGH | 8.7 | 0.3% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the t... |
| CVE-2026-44551 | CRITICAL | 9.1 | 1.5% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the L... |
| CVE-2026-44550 | MEDIUM | 5 | 0.3% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Folde... |
| CVE-2026-8686 | CRITICAL | 9.1 | 0.4% | May 15, 2026 | Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a den... |
| CVE-2026-4054 | MEDIUM | 6.5 | 0.2% | May 15, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to validate the response body of proxie... |
| CVE-2026-4053 | MEDIUM | 4.3 | 0.2% | May 15, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fiel... |
| CVE-2026-46408 | HIGH | 7.6 | 0.2% | May 15, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3... |
| CVE-2026-46407 | HIGH | 8.1 | 0.2% | May 15, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3... |
| CVE-2026-46367 | HIGH | 8.3 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in Utils::parseUrl() that allows authenticate... |
| CVE-2026-46366 | HIGH | 8.7 | 0.3% | May 15, 2026 | phpMyFAQ before 4.1.2 contains an information disclosure vulnerability in the getIdFromSolutionId() method that lacks pe... |
| CVE-2026-46365 | MEDIUM | 5.4 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains a missing authorization vulnerability in the DELETE /admin/api/content/tags/{tagId} endpo... |
| CVE-2026-46364 | CRITICAL | 9.8 | 1.7% | May 15, 2026 | phpMyFAQ before 4.1.2 contains an unauthenticated SQL injection vulnerability in BuiltinCaptcha::garbageCollector() and ... |
| CVE-2026-46363 | MEDIUM | 5.4 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that byp... |
| CVE-2026-46362 | HIGH | 7.1 | 0.3% | May 15, 2026 | phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermiss... |
| CVE-2026-46361 | HIGH | 8.2 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and resu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now