2026 CVE Vulnerabilities

67,248 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-15890MEDIUM5.3The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead...
CVE-2026-94588MEDIUM4.4In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is...
CVE-2026-94572CRITICAL9.4In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field...
CVE-2026-94571CRITICAL9.4In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redir...
CVE-2026-94424HIGH8.8A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_14000...
CVE-2026-93433MEDIUM5.5A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specia...
CVE-2026-88746HIGH7.1idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_deal.php.
CVE-2026-88745MEDIUM6.1EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.
CVE-2026-88467MEDIUM6.2CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of va...
CVE-2026-88412MEDIUM5.3An integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c) of FalkorDB (Redis module) v4.20.1 allows...
CVE-2026-88411HIGH7.5Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 lead...
CVE-2026-88410HIGH7.1The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected ...
CVE-2026-88409HIGH8.8FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix functio...
CVE-2026-88408MEDIUM6.5FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/...
CVE-2026-88407HIGH7.5An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20...
CVE-2026-88406HIGH7.5FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses func...
CVE-2026-88405CRITICAL9.8A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-funct...
CVE-2026-88404CRITICAL9.8A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execut...
CVE-2026-88403MEDIUM6.5A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to...
CVE-2026-88402CRITICAL9.8A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database ...
CVE-2026-79919MEDIUM6.3MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, function-library code running under th...
CVE-2026-79918MEDIUM6.3MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox ho...
CVE-2026-79917MEDIUM6.5MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_id}/chat/{...
CVE-2026-79916CRITICAL9.1MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject con...
CVE-2026-79317MEDIUM4.8A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and aut...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now