2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-42884MEDIUM4.3Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/collections and GET /api/col...
CVE-2026-42883MEDIUM6.5Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/libraries/:id/download endpo...
CVE-2026-42882CRITICAL9.4oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused ...
CVE-2026-42876MEDIUM4.9External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete...
CVE-2026-42875MEDIUM5.3External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete...
CVE-2026-42874LOW3.7Microdot is a minimalistic Python web framework. Prior to 2.6.1, the Response.set_cookie() method does not sanitize its ...
CVE-2026-42873NONE0WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, when attempting to upload a file with m...
CVE-2026-42872MEDIUM6.1WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a reflected Cross-Site Scripting (XSS) v...
CVE-2026-42870MEDIUM6.4WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a Stored Cross-Site Scripting (XSS) flaw...
CVE-2026-42869CRITICAL10SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57,...
CVE-2026-42565MEDIUM4.3@workos/authkit-session is a toolkit for building WorkOS AuthKit framework integrations. Prior to 0.5.1, an open redirec...
CVE-2026-42050MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9...
CVE-2026-36734HIGH8.8EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can su...
CVE-2026-2614HIGH7.5A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 ...
CVE-2026-8318MEDIUM5.5A security flaw has been discovered in VectifyAI PageIndex up to f50e52975313c6716c02b20a119577a1929decba. Affected by t...
CVE-2026-7790HIGH7.5Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. T...
CVE-2026-45224HIGH7.1Crabbox before 0.9.0 contains a path traversal vulnerability in the Islo provider's workspace path resolution that allow...
CVE-2026-45223HIGH8.8Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path whe...
CVE-2026-45222MEDIUM6.9Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with def...
CVE-2026-43969LOW3.2Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request split...
CVE-2026-43968MEDIUM4Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splittin...
CVE-2026-42871MEDIUM6.9WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, atendido/familiar_docfamiliar.php displa...
CVE-2026-42866MEDIUM6.7Tookie is a advanced OSINT information gathering tool. Prior to 4.1fix, modules/modules.py's write_txt, write_csv, write...
CVE-2026-42864CRITICAL9.9FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint ...
CVE-2026-8305CRITICAL9.8A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookR...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now