2026 CVE Vulnerabilities

67,113 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4953HIGH7.3A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/...
CVE-2026-33766MEDIUM6.5WWBN AVideo is an open source video platform. In versions up to and including 26.0, `isSSRFSafeURL()` validates URLs aga...
CVE-2026-33764MEDIUM4.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the AI plugin's `save.json.php` endp...
CVE-2026-33763MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_corre...
CVE-2026-33761MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in t...
CVE-2026-33759MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.ph...
CVE-2026-33758MEDIUM6.1OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that h...
CVE-2026-33757HIGH8.3OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for ...
CVE-2026-33755HIGH8.8Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, a...
CVE-2026-33750HIGH7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, ...
CVE-2026-33748HIGH7.5BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P...
CVE-2026-33433HIGH8.8Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.42, 3.6.11, and 3.7.0-ea.3, when `headerField...
CVE-2026-33284MEDIUM4.3GlobaLeaks is free and open-source whistleblowing software. Prior to version 5.0.89, the /api/support endpoint of GlobaL...
CVE-2026-33206MEDIUM6.3calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9....
CVE-2026-33205MEDIUM5.5calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9....
CVE-2026-30689MEDIUM4.3In Blog.Core through bcb4d17, the getinfobytoken API interface contains improper access control that leads to sensitive ...
CVE-2026-30637HIGH7.5Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and b...
CVE-2026-30407——Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv...
CVE-2026-30304CRITICAL9.6In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute al...
CVE-2026-30303CRITICAL9.8The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist se...
CVE-2026-29871HIGH7.5A path traversal vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251...
CVE-2026-28375MEDIUM6.5A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
CVE-2026-27880HIGH7.5The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory cra...
CVE-2026-27879MEDIUM6.5A resample query can be used to trigger out-of-memory crashes in Grafana.
CVE-2026-27877HIGH7.5When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being u...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now