2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-42345HIGH7.7FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packa...
CVE-2026-42344MEDIUM6.3FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packa...
CVE-2026-42343MEDIUM6.3FastGPT is an AI Agent building platform. In versions 4.14.13 and prior, the code-sandbox component suffers from insuffi...
CVE-2026-42339HIGH7.1New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.1...
CVE-2026-42307MEDIUM4.4Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists...
CVE-2026-42302CRITICAL9.8FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of...
CVE-2026-42298CRITICAL9.8Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Pu...
CVE-2026-42291MEDIUM6.8SysReptor is a fully customizable pentest reporting platform. From version 2026.4 to before version 2026.27, the endpoin...
CVE-2026-42224HIGH7.6ipl/web is a set of common web components for php projects. Prior to versions 0.13.1 and 0.10.3, the vulnerability allow...
CVE-2026-41682MEDIUM6.9pupnp is an SDK for development of UPnP device and control point applications. Prior to version 1.18.5, pupnp is vulnera...
CVE-2026-41520MEDIUM4.4Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1....
CVE-2026-41432HIGH8.2New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio...
CVE-2026-42287CRITICAL10Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and u...
CVE-2026-42286HIGH8.4Emlog is an open source website building system. Prior to version 2.6.11, missing CSRF protection in critical admin func...
CVE-2026-42213MEDIUM5.1SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0....
CVE-2026-42212HIGH7.1SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0....
CVE-2026-42209MEDIUM6.5FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.1, a remote client with reta...
CVE-2026-42206MEDIUM5.7Roadiz is a polymorphic content management system based on a node system. Prior to versions 2.3.43, 2.5.45, 2.6.31, and ...
CVE-2026-42205HIGH8.8Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulne...
CVE-2026-42202MEDIUM6.5nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-...
CVE-2026-42199MEDIUM6.2Grid is a data structure grid for rust. From version 0.17.0 to before version 1.0.1, an integer overflow in Grid::expand...
CVE-2026-42195LOW3.4draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the draw.io client accepts...
CVE-2026-42193CRITICAL9.1Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accep...
CVE-2026-42192MEDIUM5.4Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (X...
CVE-2026-41517NONE0Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows at...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now