2026 CVE Vulnerabilities

45,110 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-52747HIGH8.6ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to ...
CVE-2026-49394HIGH7.1Frappe is a full-stack web application framework. Prior to 16.19.0, authorization bypass was possible via the update_pag...
CVE-2026-49213HIGH8.1TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/src/ssrf/validateHtt...
CVE-2026-44795HIGH8.8Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3...
CVE-2026-41482HIGH7.1Frappe is a full-stack web application framework. Prior to 16.18.3, possible path traversal and local file inclusion wer...
CVE-2026-15081HIGH7.4Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Se...
CVE-2026-13244HIGH8.1Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Ma...
CVE-2026-7639HIGH7.8Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use afte...
CVE-2026-58499HIGH8.2EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS is vulnerable to path traversal in the POST /api/v1/memory...
CVE-2026-57574HIGH7.4Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-...
CVE-2026-57220HIGH7.5RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configur...
CVE-2026-57219HIGH7.5RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth en...
CVE-2026-57215HIGH8.8RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindi...
CVE-2026-57212HIGH7.7RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP ...
CVE-2026-55881HIGH7.1OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3...
CVE-2026-55880HIGH7.1OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran...
CVE-2026-55665HIGH8.5Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, Grist contained two cross-site scri...
CVE-2026-55659HIGH7.7Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, several server-rendered Grist pages...
CVE-2026-55405HIGH7.6LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.1...
CVE-2026-55233HIGH7.5OpenResty is a high performance web platform. From 1.29.2.1 to before 1.29.2.5, an out-of-bounds write vulnerability exi...
CVE-2026-55229HIGH7.5Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.34.0, Gotenberg's /forms/libreoffice/convert endpo...
CVE-2026-55213HIGH7.5h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f...
CVE-2026-45203HIGH7.8Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memor...
CVE-2026-45196HIGH7.8Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU r...
CVE-2026-41154HIGH7.8Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now