2026 CVE Vulnerabilities

45,232 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-7639HIGH7.8Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use afte...
CVE-2026-58499HIGH8.2EverOS is a memory runtime for agents. Prior to 1.0.1, EverOS is vulnerable to path traversal in the POST /api/v1/memory...
CVE-2026-57574HIGH7.4Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-...
CVE-2026-57220HIGH7.5RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, the RabbitMQ stream listener does not enforce the configur...
CVE-2026-57219HIGH7.5RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth en...
CVE-2026-57215HIGH8.8RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindi...
CVE-2026-57212HIGH7.7RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP ...
CVE-2026-55881HIGH7.1OpenReplay is a self-hosted session replay suite. From 1.22.0 before 1.27.0, getFirstMob returned 15-second presigned S3...
CVE-2026-55880HIGH7.1OpenReplay is a self-hosted session replay suite. In 1.27.0 and earlier, three dashboard and note mutation functions ran...
CVE-2026-55665HIGH8.5Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, Grist contained two cross-site scri...
CVE-2026-55659HIGH7.7Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, several server-rendered Grist pages...
CVE-2026-55405HIGH7.6LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.1...
CVE-2026-55233HIGH7.5OpenResty is a high performance web platform. From 1.29.2.1 to before 1.29.2.5, an out-of-bounds write vulnerability exi...
CVE-2026-55229HIGH7.5Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.34.0, Gotenberg's /forms/libreoffice/convert endpo...
CVE-2026-55213HIGH7.5h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f...
CVE-2026-45203HIGH7.8Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memor...
CVE-2026-45196HIGH7.8Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a GPU r...
CVE-2026-41154HIGH7.8Software installed and run as a non-privileged user may cause OOB kernel memory reads or writes through GPU API calls. ...
CVE-2026-34196HIGH7.8Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an integer overflow a...
CVE-2026-57850HIGH8.7RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a l...
CVE-2026-55827HIGH8.8FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.1, FreeRDP clients launched with the non-...
CVE-2026-55789HIGH8.5Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML app...
CVE-2026-55466HIGH8.7Snipe-IT is an IT asset/license management system. Prior to 8.6.2, UploadFileRequest sanitizes SVG content only when PHP...
CVE-2026-55452HIGH7.3Snipe-IT is an IT asset/license management system. Prior to 8.5.0, Actionlog::logaction() stores the request User-Agent ...
CVE-2026-55377HIGH8.1Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's Account Center step-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now