2026 CVE Vulnerabilities

67,228 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-77637LOW3.8Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET("wopi") and tool.POST("mail") i...
CVE-2026-77633HIGH7.1Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs...
CVE-2026-77621CRITICAL9.3Vector is a high-performance observability data pipeline. From 0.10.0 until 0.57.0, the file sink renders its templated ...
CVE-2026-77620HIGH8.7Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source feeds each decom...
CVE-2026-77619HIGH8.7Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source reads a 32-bit c...
CVE-2026-75608HIGH7.7Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/go2rtc/api in docker...
CVE-2026-75607HIGH8.1Frigate is an open source network video recorder. Prior to 0.17.2, the WebSocket handler in frigate/comms/ws.py forwards...
CVE-2026-75517MEDIUM6.5Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu integration mutation use...
CVE-2026-75511MEDIUM5.3Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu accepts chat webhook URL...
CVE-2026-75510MEDIUM5.1Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu's @novu/js In-App Inbox ...
CVE-2026-70410HIGH8.8Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite Avati...
CVE-2026-63374CRITICAL9.3AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Pri...
CVE-2026-56681HIGH7.39Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without ...
CVE-2026-95754MEDIUM6.9In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentica...
CVE-2026-95703MEDIUM5.1In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem pro...
CVE-2026-95701MEDIUM5.1In MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path co...
CVE-2026-95698MEDIUM5.3The findOrgImage method in MISP's OrgImgHelper constructs a filesystem path by concatenating a user-supplied organizatio...
CVE-2026-95697MEDIUM5.3MISP contains an authorization flaw in the Organisation model's captureOrg method. When the $force parameter is set to t...
CVE-2026-95693MEDIUM5.3In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), ...
CVE-2026-95685MEDIUM5.3MISP contains an access control flaw in the EventReports functionality. The replaceSuggestionInReport action, which allo...
CVE-2026-95683MEDIUM5.3In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes. The enrich...
CVE-2026-95501MEDIUM4.3A vulnerability was found in mtrano APENCMS up to 6546096d354153309693efabb9a0d824628ed4f5. The affected element is the ...
CVE-2026-95500HIGH7.3A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file...
CVE-2026-94570MEDIUM5.9SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decod...
CVE-2026-94127CRITICAL9.8When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now