2026 CVE Vulnerabilities

69,961 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-1128MEDIUM4.3The WP eCommerce WordPress plugin through 3.15.1 does not have CSRF check in place when deleting coupons, which could al...
CVE-2026-29084MEDIUM4.6Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, th...
CVE-2026-29061MEDIUM5.4Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a ...
CVE-2026-29060MEDIUM5Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a ...
CVE-2026-28794CRITICAL9.8oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior to version 1....
CVE-2026-28787CRITICAL9OneUptime is a solution for monitoring and managing online services. In version 10.0.11 and prior, the WebAuthn authenti...
CVE-2026-28785CRITICAL9.8Ghostfolio is an open source wealth management software. Prior to version 2.244.0, by bypassing symbol validation, an at...
CVE-2026-28685MEDIUM6.5Kimai is a web-based multi-user time-tracking application. Prior to version 2.51.0, "GET /api/invoices/{id}" only checks...
CVE-2026-28683HIGH8.7Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, if...
CVE-2026-28682MEDIUM6.4Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, th...
CVE-2026-28681HIGH8.1Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From ve...
CVE-2026-28680CRITICAL9.3Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual as...
CVE-2026-28679HIGH7.5Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0,...
CVE-2026-28677HIGH8.2OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version...
CVE-2026-28676HIGH8.8OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version...
CVE-2026-28675MEDIUM5.3OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version...
CVE-2026-28509MEDIUM5.4LangBot is a global IM bot platform designed for LLMs. Prior to version 4.8.7, LangBot’s web UI renders user-supplied ra...
CVE-2026-28508HIGH8.6Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CS...
CVE-2026-28507HIGH7.2Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained...
CVE-2026-28429HIGH7.5Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871, a Path Traversal vulnerability was identified i...
CVE-2026-28428MEDIUM5.3Talishar is a fan-made Flesh and Blood project. Prior to commit a9c218e, an authentication bypass vulnerability in Talis...
CVE-2026-27605MEDIUM5.4Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-27603HIGH7.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-27005CRITICAL9.8Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-25888HIGH8.8Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now