2026 CVE Vulnerabilities

45,125 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-47376MEDIUM5.1NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the password-reset page rendered the URL ...
CVE-2026-47375MEDIUM6NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, an authenticated user with columnAdd perm...
CVE-2026-47279MEDIUM6.9NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, the public shared-view relation endpoints...
CVE-2026-46552MEDIUM5.8NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, shared-base sessions were granted the sam...
CVE-2026-46551MEDIUM6.5NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, the uploadViaURL path in the v1/v2 attach...
CVE-2026-46550MEDIUM5.4NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the refresh-token cookie was set with htt...
CVE-2026-46548MEDIUM4.3NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the request-filtering-agent SSRF protecti...
CVE-2026-46547MEDIUM6.1NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, a reflected XSS vulnerability exists in t...
CVE-2026-12892MEDIUM4.4A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing...
CVE-2026-12891MEDIUM4.3A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a cra...
CVE-2026-11820MEDIUM6.5A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the ...
CVE-2026-11819MEDIUM5.5Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module...
CVE-2026-54325MEDIUM4.4Pi is a minimal terminal coding harness. Pi before 0.79.0 loaded project-local configuration and resources from a reposi...
CVE-2026-45792MEDIUM5.5rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.32.0, RTK (Rust Token Killer) ...
CVE-2026-55736MEDIUM5.9Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a...
CVE-2026-54319MEDIUM4.2Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1...
CVE-2026-55517MEDIUM4.3Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.5, a Deno program that opens a client WebSocket ...
CVE-2026-54324MEDIUM6.5Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1...
CVE-2026-54323MEDIUM5.9Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1...
CVE-2026-54022MEDIUM5.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the ...
CVE-2026-54021MEDIUM6.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, sever...
CVE-2026-54019MEDIUM6.5Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ...
CVE-2026-54016MEDIUM4.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ...
CVE-2026-54015MEDIUM6.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ...
CVE-2026-54014MEDIUM4.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, a pat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now