2026 CVE Vulnerabilities

65,328 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-100882LOW2.4A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Web...
CVE-2026-100881LOW2.6A security vulnerability has been detected in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown proce...
CVE-2026-96281MEDIUM6.2On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older ...
CVE-2026-96280HIGH7.5The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (...
CVE-2026-101090CRITICAL9.8Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard...
CVE-2026-101089LOW3.1Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the...
CVE-2026-101088MEDIUM5.3Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/s...
CVE-2026-101087MEDIUM4.3Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS web...
CVE-2026-101086MEDIUM6.5Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing aut...
CVE-2026-101085MEDIUM6.5Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users...
CVE-2026-101084CRITICAL9.6obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticat...
CVE-2026-101065CRITICAL9.8Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart ...
CVE-2026-101064HIGH7.6Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows p...
CVE-2026-101063MEDIUM5.3Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authen...
CVE-2026-101062HIGH8.8Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dyn...
CVE-2026-100880LOW3.5A weakness has been identified in zhistaredu StarTraining up to 3.8.1. This vulnerability affects unknown code of the fi...
CVE-2026-100879MEDIUM4.3A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the function checkRoleAllowed o...
CVE-2026-100878MEDIUM6.3A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Affected by this issue is the function SysUser.is...
CVE-2026-100877MEDIUM4.3A vulnerability was determined in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be...
CVE-2026-96279MEDIUM6.5A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates...
CVE-2026-100876MEDIUM6.3A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Aff...
CVE-2026-100875HIGH7.3A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be...
CVE-2026-100874HIGH7.3A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This af...
CVE-2026-100873MEDIUM4.3A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. ...
CVE-2026-101061MEDIUM4.7utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incompl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now