2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-42595HIGH8.6Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/f...
CVE-2026-42594HIGH7.5Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine th...
CVE-2026-42593MEDIUM5.3Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoff...
CVE-2026-42592MEDIUM5.3Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, FilterOutboundURL resolves the hostname, che...
CVE-2026-42591HIGH8.2Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/...
CVE-2026-42590HIGH8.2Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.30.0, The ExifTool metadata write blocklist in Got...
CVE-2026-42589CRITICAL9.8Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write...
CVE-2026-42283HIGH7.8DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI se...
CVE-2026-42281HIGH8.6MagicMirror² is an open source modular smart mirror platform. Prior to 2.36.0, an unauthenticated Server-Side Request Fo...
CVE-2026-42159MEDIUM5.4Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri...
CVE-2026-40893HIGH8.2Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly ...
CVE-2026-44484CRITICAL9.8PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introdu...
CVE-2026-44482CRITICAL9.6soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8...
CVE-2026-44375HIGH7.5Nerdbank.MessagePack is a NativeAOT-compatible MessagePack serialization library. Prior to 1.1.62, Nerdbank.MessagePack ...
CVE-2026-44374MEDIUM4.3Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints ...
CVE-2026-44371MEDIUM5.3Open OnDemand is an open-source high-performance computing portal. Prior to 4.0.11, 4.1.5, and 4.2.2, specially crafted ...
CVE-2026-44308MEDIUM6.3Spring Cloud AWS simplifies using AWS managed services in a Spring and Spring Boot applications. From 3.0.0 to 4.0.1, pp...
CVE-2026-44216HIGH7.5Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and 44.0.1, Wasmtime's allocation logic for a WebA...
CVE-2026-42881HIGH8.4STIGQter is an open-source reimplementation of DISA's STIG Viewer. From 0.1.2 to before 1.2.7, an attacker can achieve l...
CVE-2026-42559HIGH8.8RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate's Streamable HTTP se...
CVE-2026-42457CRITICAL9vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prio...
CVE-2026-42186HIGH7.5OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace del...
CVE-2026-41937HIGH8.6Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_...
CVE-2026-41935HIGH7.1Vvveb before 1.0.8.3 contains an uncontrolled recursion vulnerability in the admin controller dispatch cycle where Base:...
CVE-2026-41933MEDIUM6.9Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attac...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now