2026 CVE Vulnerabilities

47,636 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-72912MEDIUM4.3CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-rec...
CVE-2026-72911CRITICAL9.9ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.118.0 and 16.29.0, the validate_templat...
CVE-2026-72910HIGH7.1ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, p...
CVE-2026-72909HIGH7.1ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayabl...
CVE-2026-72908MEDIUM6.5ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template...
CVE-2026-72907MEDIUM6.5ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function ...
CVE-2026-72906MEDIUM4.3ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email ...
CVE-2026-72905Rejected reason: Further research determined the issue is not a vulnerability.
CVE-2026-72904CRITICAL9.3Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file ...
CVE-2026-72903HIGH8.1Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can retu...
CVE-2026-72743MEDIUM5.4SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashb...
CVE-2026-63622HIGH7.8A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploi...
CVE-2026-48160CRITICAL9.3react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the defau...
CVE-2026-19411LOW3.9A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could al...
CVE-2026-18982HIGH8.8A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in a...
CVE-2026-18951HIGH8.8A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly ag...
CVE-2026-18950HIGH8.8A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how Rol...
CVE-2026-18949HIGH8.8A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Ac...
CVE-2026-18948CRITICAL9.9A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, whic...
CVE-2026-18947HIGH8.5A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental...
CVE-2026-18942MEDIUM5.5A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. Th...
CVE-2026-18941HIGH7.7A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is...
CVE-2026-18621HIGH7.6A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security harde...
CVE-2026-18620HIGH7.1A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerab...
CVE-2026-18618HIGH7.5A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to kn...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now