2026 CVE Vulnerabilities

65,722 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5382LOW3An issue that could expose records outside of the authorized organization scope through the MCP endpoints has been resol...
CVE-2026-5381LOW2.2An issue that could expose task information outside of the authorized organization scope has been resolved. This is an i...
CVE-2026-5380MEDIUM5.3An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields ...
CVE-2026-5379LOW3An issue that allowed MCP agents to access certificate information from outside of their authorized organization scope h...
CVE-2026-5378MEDIUM6.8An issue that allowed administrators to create and update users outside of their authorized organization scope has been ...
CVE-2026-5376MEDIUM5.9An issue that could prevent session inactivity timeouts from triggering due to automatic page reloading has been resolve...
CVE-2026-5375LOW2.7An issue that could allow a user with access to a credential to view sensitive fields through an API response has been r...
CVE-2026-5374MEDIUM5.8An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization...
CVE-2026-5373HIGH8.4An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is...
CVE-2026-5372MEDIUM6.4An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This ...
CVE-2026-4740HIGH8.2A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). ...
CVE-2026-4292LOW2.7An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `Mod...
CVE-2026-4277CRITICAL9.8An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model i...
CVE-2026-3902HIGH7.5An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote att...
CVE-2026-35485HIGH7.5text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate...
CVE-2026-35484MEDIUM5.3text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate...
CVE-2026-35483MEDIUM5.3text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticate...
CVE-2026-35481——Rejected reason: Further research determined the issue does not satisfy the assignment rules.
CVE-2026-35480MEDIUM6.2go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec ...
CVE-2026-35464HIGH7.5pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTI...
CVE-2026-35463HIGH8.8pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTION...
CVE-2026-35462MEDIUM4.3Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are...
CVE-2026-35461MEDIUM4.3Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, the Papra webhook system allows aut...
CVE-2026-35460MEDIUM5.4Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, transactional email templates in Pa...
CVE-2026-35458CRITICAL9.8Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile us...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now