2026 CVE Vulnerabilities

67,227 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-43643HIGH7.5Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing m...
CVE-2026-43642HIGH8.1Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing mo...
CVE-2026-43641CRITICAL9.8Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing m...
CVE-2026-18626MEDIUM6.8Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affect...
CVE-2026-18462HIGH7.3Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allow...
CVE-2026-18461CRITICAL9.2Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format Stri...
CVE-2026-18460MEDIUM6.9Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers...
CVE-2026-18459HIGH8.7Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality. Th...
CVE-2026-18458MEDIUM6.8Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type ...
CVE-2026-18457HIGH8.3Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issu...
CVE-2026-11389MEDIUM6.8Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type ...
CVE-2026-11388MEDIUM6.9Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation. This issue affects Conn...
CVE-2026-95818LOW3.6A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allo...
CVE-2026-94456CRITICAL9.1Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The ...
CVE-2026-94455HIGH7.1An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The a...
CVE-2026-87902HIGH8.1An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.ph...
CVE-2026-86062MEDIUM6.1LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieva...
CVE-2026-86059CRITICAL9.6Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Gi...
CVE-2026-85740HIGH7.1LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parse...
CVE-2026-85734CRITICAL9.1LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/a...
CVE-2026-85725MEDIUM5.9LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwo...
CVE-2026-85709MEDIUM5.3LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Py...
CVE-2026-84301MEDIUM6.3FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios...
CVE-2026-83803HIGH7.7Sentry is an error tracking and performance monitoring tool. From 23.11.0 until 26.7.0, Sentry instances with the reloca...
CVE-2026-83603HIGH8.4Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-sta...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now