2026 CVE Vulnerabilities

47,565 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-73035MEDIUM5.3npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability t...
CVE-2026-73033HIGH7Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmi...
CVE-2026-73030HIGH8.1unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory func...
CVE-2026-72913HIGH7.3Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/wind...
CVE-2026-72912MEDIUM4.3CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-rec...
CVE-2026-72911CRITICAL9.9ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_templat...
CVE-2026-72910HIGH7.1ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, p...
CVE-2026-72909HIGH7.1ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayabl...
CVE-2026-72908MEDIUM6.5ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template...
CVE-2026-72907MEDIUM6.5ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function ...
CVE-2026-72906MEDIUM4.3ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email ...
CVE-2026-72905Rejected reason: Further research determined the issue is not a vulnerability.
CVE-2026-72904CRITICAL9.3Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file ...
CVE-2026-72903HIGH8.1Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can retu...
CVE-2026-72743MEDIUM5.4SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashb...
CVE-2026-63622HIGH7.8A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploi...
CVE-2026-48160CRITICAL9.3react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the defau...
CVE-2026-19411LOW3.9A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could al...
CVE-2026-18982HIGH8.8A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in a...
CVE-2026-18951HIGH8.8A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly ag...
CVE-2026-18950HIGH8.8A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how Rol...
CVE-2026-18949HIGH8.8A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Ac...
CVE-2026-18948CRITICAL9.9A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, whic...
CVE-2026-18947HIGH8.5A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental...
CVE-2026-18942MEDIUM5.5A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. Th...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now