2026 CVE Vulnerabilities

65,328 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40252HIGH8.1FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any...
CVE-2026-40242MEDIUM6.5Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.17.3, the /api/template...
CVE-2026-40194LOW3.7phpseclib is a PHP secure communications library. Starting in 0.1.1 and prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\N...
CVE-2026-40191MEDIUM6.8ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to 5.0.4-beta...
CVE-2026-40190CRITICAL9.8LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.5.18, the LangSmith JavaScri...
CVE-2026-40189CRITICAL9.8goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.4, goshs enforces the documented per-folder .goshs ACL/ba...
CVE-2026-40188HIGH7.7goshs is a SimpleHTTPServer written in Go. From 1.0.7 to before 2.0.0-beta.4, the SFTP command rename sanitizes only the...
CVE-2026-40185MEDIUM6.5TREK is a collaborative travel planner. Prior to 2.7.2, TREK was missing authorization checks on the Immich trip photo m...
CVE-2026-40184MEDIUM5.3TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requiring authentication. Th...
CVE-2026-40180HIGH7.5Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to 2....
CVE-2026-40178MEDIUM5.9ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was a...
CVE-2026-40177HIGH7.5ajenti.plugin.core defines all necessary core elements to allow Ajenti to run properly. Prior to 0.112, if the 2FA was a...
CVE-2026-40175MEDIUM4.8Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a...
CVE-2026-40168HIGH8.2Postiz is an AI social media scheduling tool. Prior to 2.21.5, the /api/public/stream endpoint is vulnerable to SSRF. Al...
CVE-2026-39922MEDIUM6.3GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vuln...
CVE-2026-39921MEDIUM6.3GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows a...
CVE-2026-32252HIGH7.7Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-30232CRITICAL9.6Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-3446MEDIUM6When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded...
CVE-2026-33737MEDIUM6.5Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string()...
CVE-2026-33736MEDIUM6.5Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including ROLE_STUDENT) can en...
CVE-2026-33710HIGH7.5Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are generated using md5(time...
CVE-2026-33708MEDIUM6.5Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns...
CVE-2026-33707CRITICAL9.8Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism gener...
CVE-2026-33706HIGH7.1Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user with a REST API key can modify the...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now