2026 CVE Vulnerabilities

66,324 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-22664HIGH7.7prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in the Fal.ai media status pol...
CVE-2026-22663HIGH8.7prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate che...
CVE-2026-22662MEDIUM5.3prompts.chat prior to commit 1464475 contains a blind server-side request forgery vulnerability in the Wiro media genera...
CVE-2026-22661HIGH8.6prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability in skill file handling that allows attacker...
CVE-2026-5484MEDIUM5.5A weakness has been identified in BookStackApp BookStack up to 26.03. Affected is the function chapterToMarkdown of the ...
CVE-2026-28798CRITICAL10ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. Prior to version 1.5.3, a...
CVE-2026-25726CRITICAL9.8Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak ps...
CVE-2026-3184MEDIUM5.3A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h`...
CVE-2026-2625MEDIUM5.5A flaw was found in rust-rpm-sequoia. An attacker can exploit this vulnerability by providing a specially crafted Red Ha...
CVE-2026-5476MEDIUM4.6A vulnerability was identified in NASA cFS up to 7.0.0 on 32-bit. Affected is the function CFE_TBL_ValidateCodecLoadSize...
CVE-2026-5475MEDIUM5.5A vulnerability was determined in NASA cFS up to 7.0.0. This impacts the function CFE_SB_TransmitMsg of the file cfe_sb_...
CVE-2026-32186CRITICAL9.8Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a networ...
CVE-2026-0545CRITICAL9.8In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authoriz...
CVE-2026-5474HIGH8.8A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw...
CVE-2026-5473HIGH7A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the componen...
CVE-2026-28373CRITICAL9.6The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryp...
CVE-2026-5472MEDIUM6.3A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Th...
CVE-2026-5471LOW3.3A vulnerability was detected in Investory Toy Planet Trouble App up to 1.5.5 on Android. Impacted is an unknown function...
CVE-2026-5470MEDIUM6.3A security vulnerability has been detected in mixelpixx Google-Research-MCP 1e062d7bd887bfe5f6e582b6cc288bb897b35cf2/ca6...
CVE-2026-35218HIGH8.7Budibase is an open-source low-code platform. Prior to version 3.32.5, Budibase's Builder Command Palette renders entity...
CVE-2026-35216CRITICAL9Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Co...
CVE-2026-35214HIGH8.7Budibase is an open-source low-code platform. Prior to version 3.33.4, the plugin file upload endpoint (POST /api/plugin...
CVE-2026-31818CRITICAL9.9Budibase is an open-source low-code platform. Prior to version 3.33.4, a server-side request forgery (SSRF) vulnerabilit...
CVE-2026-31404——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-31403HIGH7.8In the Linux kernel, the following vulnerability has been resolved: NFSD: Hold net reference for the lifetime of /proc/...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now