2026 CVE Vulnerabilities

44,809 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-32718MEDIUM6.5Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-59711MEDIUM6.1showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitr...
CVE-2026-55514MEDIUM6.5vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a...
CVE-2026-54764MEDIUM5.8Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middle...
CVE-2026-50135MEDIUM5.5Hugo is a static site generator. From 0.123.0 to 0.161.1, a regression made  RootMappingFs.statRoot  use  Stat  (follows...
CVE-2026-48267MEDIUM5.5DNG SDK versions 1.7.1 2536 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an...
CVE-2026-33734MEDIUM6.9FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injecti...
CVE-2026-21384MEDIUM5.3Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported ...
CVE-2026-21370MEDIUM5.3Memory Corruption when validating input batch size and buffer plane count exceeds maximum allowed values.
CVE-2026-21369MEDIUM5.3Memory Corruption when handling flash commands due to outdated LED count values being used after userspace modification.
CVE-2026-21368MEDIUM5.3Memory Corruption when parsing jpeg commands due to unaccounted extra writes to the buffer during validation checks.
CVE-2026-59089MEDIUM5.5A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calc...
CVE-2026-58404MEDIUM6.8Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests t...
CVE-2026-58403MEDIUM6.5Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files und...
CVE-2026-58402MEDIUM5.4Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-f...
CVE-2026-55646MEDIUM6.5vLLM is an inference and serving engine for large language models. From 0.22.0 to 0.23.0, the /v1/audio/transcriptions a...
CVE-2026-50134MEDIUM5.8Hugo is a static site generator. From 0.91.0 until 0.162.0, resources.GetRemote enforces security.http.urls on the URL i...
CVE-2026-50133MEDIUM6.1Hugo is a static site generator. Prior to 0.162.0, Hugo accepts content files in several markup formats. Files mapped to...
CVE-2026-44362MEDIUM5.5OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-14898MEDIUM6.5The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could pl...
CVE-2026-55798MEDIUM4.5Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by ...
CVE-2026-54291MEDIUM5.9pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections ...
CVE-2026-12154MEDIUM6.4The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
CVE-2026-40257MEDIUM5.5OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-59152MEDIUM5LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can se...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now