2026 CVE Vulnerabilities

67,111 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33868MEDIUM6.1Mastodon is a free, open-source social network server based on ActivityPub. Prior to versions 4.5.8, 4.4.15, and 4.3.21,...
CVE-2026-33765CRITICAL9.8Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic...
CVE-2026-33739MEDIUM4.8FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.1812, the listing ta...
CVE-2026-33654CRITICAL9.8nanobot is a personal AI assistant. Prior to version 0.1.6, an indirect prompt injection vulnerability exists in the ema...
CVE-2026-33045MEDIUM5.4Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 20...
CVE-2026-33044MEDIUM5.4Home Assistant is open source home automation software that puts local control and privacy first. Starting in version 20...
CVE-2026-32241HIGH8.8Flannel is a network fabric for containers, designed for Kubernetes. The Flannel project includes an experimental Extens...
CVE-2026-31951MEDIUM5.7LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc1 through 0.8.3-rc1, user-created MCP (Model ...
CVE-2026-31950MEDIUM5.3LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoi...
CVE-2026-31945HIGH7.7LibreChat is a ChatGPT clone with additional features. Versions 0.8.2-rc2 through 0.8.2 are vulnerable to a server-side ...
CVE-2026-31943HIGH8.5LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth...
CVE-2026-4970MEDIUM6.3A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the...
CVE-2026-4969LOW3.5A vulnerability was identified in code-projects Social Networking Site 1.0. The impacted element is an unknown function ...
CVE-2026-34387CRITICAL9.8Fleet is open source device management software. Prior to 4.81.1, a command injection vulnerability in Fleet's software ...
CVE-2026-34386HIGH8.8Fleet is open source device management software. Prior to 4.81.0, a SQL injection vulnerability in Fleet's MDM bootstrap...
CVE-2026-34385HIGH8.1Fleet is open source device management software. Prior to 4.81.0, a second-order SQL injection vulnerability in Fleet's ...
CVE-2026-34375HIGH8.2WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirm...
CVE-2026-34374CRITICAL9.1WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` met...
CVE-2026-34369MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_ap...
CVE-2026-29180HIGH8.8Fleet is open source device management software. Prior to 4.81.1, a broken access control vulnerability in Fleet's host ...
CVE-2026-26061HIGH7.5Fleet is open source device management software. Prior to 4.81.0, Fleet contained multiple unauthenticated HTTP endpoint...
CVE-2026-26060HIGH8.8Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic c...
CVE-2026-4968MEDIUM4.3A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an unknown function of the file ...
CVE-2026-4966MEDIUM6.3A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. Impacted is an unknown function of the file /ad...
CVE-2026-4965CRITICAL9.8A vulnerability was detected in letta-ai letta 0.16.4. This issue affects the function resolve_type of the file letta/fu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now