2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8207HIGH7Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/gr...
CVE-2026-7652MEDIUM5.3The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery Mechanism in the unauthe...
CVE-2026-6667MEDIUM4.3PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users ...
CVE-2026-6666HIGH7.5A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response ...
CVE-2026-6665CRITICAL9.8The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the conten...
CVE-2026-6664HIGH7.5An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to ...
CVE-2026-41705HIGH8.6Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized...
CVE-2026-44313CRITICAL9.1Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. Prior...
CVE-2026-42455HIGH8.8Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In ve...
CVE-2026-45130MEDIUM5.5Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compou...
CVE-2026-44987LOW3.8SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with "User Admin" permissi...
CVE-2026-44656MEDIUM5.3Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists...
CVE-2026-44286LOW2.3FastGPT is an AI Agent building platform. Prior to version 4.14.17, an unauthenticated Server-Side Request Forgery (SSRF...
CVE-2026-44284MEDIUM6.3FastGPT is an AI Agent building platform. Prior to version 4.14.17, FastGPT had an inconsistent SSRF protection gap in M...
CVE-2026-42556CRITICAL9Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who c...
CVE-2026-42456MEDIUM4.3AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-42454CRITICAL9.9Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v...
CVE-2026-42453HIGH8.7Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v...
CVE-2026-42452HIGH8.1Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v...
CVE-2026-42451MEDIUM6.3Grimmory is a self-hosted digital library. Prior to version 2.3.1, a stored cross-site scripting (XSS) vulnerability in ...
CVE-2026-42354CRITICAL9.8Sentry is an error tracking and performance monitoring tool. From version 21.12.0 to before version 26.4.1, a critical v...
CVE-2026-42352HIGH8.6pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23...
CVE-2026-42351HIGH7.5pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23...
CVE-2026-42350MEDIUM5.1Kargo manages and automates the promotion of software artifacts. Prior to versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2, Ka...
CVE-2026-42346MEDIUM6.5Postiz is an AI social media scheduling tool. From version 2.16.6 to before version 2.21.7, all SSRF protections added i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now