2026 CVE Vulnerabilities

67,127 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33697MEDIUM6.3Cocos AI is a confidential computing system for AI. The current implementation of attested TLS (aTLS) in CoCoS is vulner...
CVE-2026-29071MEDIUM4.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8....
CVE-2026-29070HIGH8.1Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8....
CVE-2026-28788HIGH7.1Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8....
CVE-2026-28786MEDIUM4.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8....
CVE-2026-27893HIGH8.8vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to versio...
CVE-2026-4903HIGH8.8A flaw has been found in Tenda AC5 15.03.06.47. This vulnerability affects the function formQuickIndex of the file /gofo...
CVE-2026-4902HIGH8.8A vulnerability was detected in Tenda AC5 15.03.06.47. This affects the function fromAddressNat of the file /goform/addr...
CVE-2026-34352CRITICAL9.8In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users to observe or manipulate the screen contents, or ...
CVE-2026-33897CRITICAL9.9Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to...
CVE-2026-33743MEDIUM6.5Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket bac...
CVE-2026-33711HIGH7.8Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API reli...
CVE-2026-33542MEDIUM4.8Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fing...
CVE-2026-4900MEDIUM5.5A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the fil...
CVE-2026-4899LOW2.4A security flaw has been discovered in code-projects Online Food Ordering System 1.0. Affected by this issue is some unk...
CVE-2026-4898MEDIUM4.3A vulnerability was identified in code-projects Online Food Ordering System 1.0. Affected by this vulnerability is an un...
CVE-2026-4346MEDIUM6.8The vulnerability affecting TL-WR850N v3 allows cleartext storage of administrative and Wi-Fi credentials in a region of...
CVE-2026-3650HIGH8.7A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-...
CVE-2026-33687HIGH8.8Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 contain a vulnerability...
CVE-2026-33686HIGH8.8Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal v...
CVE-2026-33682MEDIUM4.8Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54....
CVE-2026-33674MEDIUM5.3PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation...
CVE-2026-33673MEDIUM5.4PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cros...
CVE-2026-33672MEDIUM5.3Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method inj...
CVE-2026-33671HIGH7.5Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now