2026 CVE Vulnerabilities

65,717 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-35520HIGH8.8FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b...
CVE-2026-35519HIGH8.8FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b...
CVE-2026-35518HIGH8.8FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b...
CVE-2026-35517HIGH8.8FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b...
CVE-2026-35516MEDIUM5LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, LinkRepository::update and CheckLinksCommand:...
CVE-2026-35515MEDIUM6.1Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.18, SseStream._transform() int...
CVE-2026-35492MEDIUM6.5Kedro-Datasets is a Kendo plugin providing data connectors. Prior to 9.3.0, PartitionedDataset in kedro-datasets was vul...
CVE-2026-35491MEDIUM6.1FTLDNS (pihole-FTL) provides an interactive API and also generates statistics for Pi-hole's Web interface. From 6.0 to b...
CVE-2026-35490CRITICAL9.8changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required...
CVE-2026-35489HIGH7.3Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, the...
CVE-2026-35488HIGH8.1Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.4, Rec...
CVE-2026-35487MEDIUM5.3text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate...
CVE-2026-35486HIGH7.5text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, he superbooga and...
CVE-2026-33816CRITICAL9.8Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVE-2026-33815CRITICAL9.8Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVE-2026-30460HIGH8.8Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in t...
CVE-2026-1079MEDIUM6A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Auto...
CVE-2026-1078HIGH7.2An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R2...
CVE-2026-5384MEDIUM5.8An issue that could allow a credential to be updated and used for a task from outside of the authorized organization sco...
CVE-2026-5383MEDIUM4.4An issue that could allow access to Explorer groups from outside of the authorized organization scope has been resolved....
CVE-2026-5382LOW3An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resol...
CVE-2026-5381LOW2.2An issue that could expose task information outside of the authorized organization scope has been resolved. This is an i...
CVE-2026-5380MEDIUM5.3An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields ...
CVE-2026-5379LOW3An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope h...
CVE-2026-5378MEDIUM6.8An issue that allowed administrators to create and update users outside of their authorized organization scope has been ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now