2026 CVE Vulnerabilities

67,248 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-79316HIGH7.6An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configur...
CVE-2026-77525MEDIUM4.2MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, management chat-record routes authorize ...
CVE-2026-77523HIGH7.4MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the model parameter form route a...
CVE-2026-77522MEDIUM4.3MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the knowledge web-document impor...
CVE-2026-77521CRITICAL10MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skil...
CVE-2026-77520MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal user in the same workspace can ...
CVE-2026-77519MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, the /chat/api/mcp authentication path lo...
CVE-2026-77518MEDIUM5MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows anothe...
CVE-2026-77517MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.10.2-lts, document and paragraph opera...
CVE-2026-77516MEDIUM5.4MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member de...
CVE-2026-73553HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-73551MEDIUM5.3Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-73511MEDIUM5.3Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-67827CRITICAL9.8Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote C...
CVE-2026-61647HIGH7.1NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content ...
CVE-2026-59816MEDIUM4.3Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7...
CVE-2026-58272MEDIUM5.3Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1...
CVE-2026-58270MEDIUM6.5Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0,...
CVE-2026-55179MEDIUM6.5Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2...
CVE-2026-55105HIGH7.7Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.1...
CVE-2026-49453HIGH7Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.1...
CVE-2026-49450HIGH7.1Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2...
CVE-2026-49449LOW2.5Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 unt...
CVE-2026-46649CRITICAL9.1Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2...
CVE-2026-85219LOW3.7Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause u...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now