2026 CVE Vulnerabilities

67,120 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-30304CRITICAL9.6In its design for automatic terminal command execution, AI Code offers two options: Execute safe commands and execute al...
CVE-2026-30303CRITICAL9.8The command auto-approval module in Axon Code contains an OS Command Injection vulnerability, rendering its whitelist se...
CVE-2026-29871HIGH7.5A path traversal vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251...
CVE-2026-28375MEDIUM6.5A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
CVE-2026-27880HIGH7.5The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory cra...
CVE-2026-27879MEDIUM6.5A resample query can be used to trigger out-of-memory crashes in Grafana.
CVE-2026-27877HIGH7.5When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being u...
CVE-2026-27876CRITICAL9.1A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impac...
CVE-2026-1496CRITICAL9.3Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that ...
CVE-2026-32859MEDIUM5.4ByteDance DeerFlow versions prior to commit 5dbb362 contain a stored cross-site scripting vulnerability in the artifacts...
CVE-2026-32695HIGH7.7Traefik is an HTTP reverse proxy and load balancer. Prior to versions 3.6.11 and 3.7.0-ea.2, Traefik's Knative provider ...
CVE-2026-4982HIGH7.3A user with permission "update world" in any Venueless world is able to exfiltrate chat messages from direct messages or...
CVE-2026-4340——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-4622CRITICAL9.8OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS command...
CVE-2026-4621MEDIUM5.6Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network.
CVE-2026-4620CRITICAL9.8OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS command...
CVE-2026-4619CRITICAL9.8Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network.
CVE-2026-4309MEDIUM6.5Missing Authorization vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to get a specific device infor...
CVE-2026-25101CRITICAL9.8Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same aft...
CVE-2026-25100MEDIUM5.4Bludit is vulnerable to Stored Cross-Site Scripting (XSS) in its image upload functionality. An authenticated attacker w...
CVE-2026-25099HIGH8.8Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension wi...
CVE-2026-3457MEDIUM6.8Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sent...
CVE-2026-27860MEDIUM5.3If auth_username_chars is empty, it is possible to inject arbitrary LDAP filter to Dovecot's LDAP authentication. This l...
CVE-2026-27859MEDIUM5.3A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably forma...
CVE-2026-27858HIGH7.5Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now