2026 CVE Vulnerabilities

47,533 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-72925MEDIUM6.1SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_mi...
CVE-2026-72922HIGH8.2AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-72921HIGH8.1SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes auth...
CVE-2026-72920CRITICAL9.8SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC s...
CVE-2026-47702CRITICAL9.1TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the bu...
CVE-2026-18860HIGH8.7Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can cr...
CVE-2026-18636MEDIUM6.8The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users fr...
CVE-2026-18635HIGH7.2Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able ...
CVE-2026-18129HIGH8.1Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a ...
CVE-2026-18127HIGH7.7External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authentica...
CVE-2026-18125HIGH7.5An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated at...
CVE-2026-17535MEDIUM6.2Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by...
CVE-2026-17061CRITICAL10A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2...
CVE-2026-73210MEDIUM5.1A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup o...
CVE-2026-51584CRITICAL9.8An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the S...
CVE-2026-51583HIGH8.5An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF...
CVE-2026-48056CRITICAL10Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 impro...
CVE-2026-48046CRITICAL9.3Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contai...
CVE-2026-46670CRITICAL9.8YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-imp...
CVE-2026-19539HIGH8.6Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5...
CVE-2026-19434MEDIUM5.1Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute ar...
CVE-2026-72785CRITICAL9.3Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only ...
CVE-2026-72784MEDIUM6.9Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulne...
CVE-2026-72783MEDIUM6.9Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakne...
CVE-2026-72782HIGH7.1Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secre...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now