2026 CVE Vulnerabilities

67,062 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33028HIGH7.5Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerabl...
CVE-2026-33027MEDIUM6.5Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly...
CVE-2026-30077HIGH7.5OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But ...
CVE-2026-29872HIGH8.2A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80...
CVE-2026-5124MEDIUM6.3A security vulnerability has been detected in osrg GoBGP up to 4.3.0. Affected is the function BGPHeader.DecodeFromBytes...
CVE-2026-29954HIGH7.6In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing th...
CVE-2026-29909MEDIUM5.3MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/f...
CVE-2026-27508MEDIUM6.1Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redire...
CVE-2026-26352MEDIUM5.4Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/v...
CVE-2026-5170MEDIUM5.3A user with access to the cluster with a limited set of privilege actions can trigger a crash of a mongod process during...
CVE-2026-5123MEDIUM6.3A weakness has been identified in osrg GoBGP up to 4.3.0. This impacts the function DecodeFromBytes of the file pkg/pack...
CVE-2026-34472HIGH7.1Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6.0.10P2_TE and V6.0.10P3N3_TE allows u...
CVE-2026-33643HIGH7.4SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the mysqlColumnAsInsert function in file pl...
CVE-2026-30562CRITICAL9.3A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-30561MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-30560MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-30559MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-30558MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-30557MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-30556MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-2287CRITICAL9.8CrewAI does not properly check that Docker is still running during runtime, and will fall back to a sandbox setting that...
CVE-2026-2286CRITICAL9.8CrewAI contains a server-side request forgery vulnerability that enables content acquisition from internal and cloud ser...
CVE-2026-2285HIGH7.5CrewAI contains a arbitrary local file read vulnerability in the JSON loader tool that reads files without path validati...
CVE-2026-2275CRITICAL9.6The CrewAI CodeInterpreter tool falls back to SandboxPython when it cannot reach Docker, which can enable RCE through ar...
CVE-2026-29953HIGH7.4SQL Injection vulnerability in SchemaHero 0.23.0 via the column parameter to the columnAsInsert function in file plugins...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now