2026 CVE Vulnerabilities

70,003 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28683HIGH8.7Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, if...
CVE-2026-28682MEDIUM6.4Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, th...
CVE-2026-28681HIGH8.1Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From ve...
CVE-2026-28680CRITICAL9.3Ghostfolio is an open source wealth management software. Prior to version 2.245.0, an attacker can exploit the manual as...
CVE-2026-28679HIGH7.5Home-Gallery.org is a self-hosted open-source web gallery to browse personal photos and videos. Prior to version 1.21.0,...
CVE-2026-28677HIGH8.2OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version...
CVE-2026-28676HIGH8.8OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version...
CVE-2026-28675MEDIUM5.3OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Prior to version...
CVE-2026-28509MEDIUM5.4LangBot is a global IM bot platform designed for LLMs. Prior to version 4.8.7, LangBot’s web UI renders user-supplied ra...
CVE-2026-28508HIGH8.6Idno is a social publishing platform. Prior to version 1.6.4, a logic error in the API authentication flow causes the CS...
CVE-2026-28507HIGH7.2Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained...
CVE-2026-28429HIGH7.5Talishar is a fan-made Flesh and Blood project. Prior to commit 6be3871, a Path Traversal vulnerability was identified i...
CVE-2026-28428MEDIUM5.3Talishar is a fan-made Flesh and Blood project. Prior to commit a9c218e, an authentication bypass vulnerability in Talis...
CVE-2026-27605MEDIUM5.4Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-27603HIGH7.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-27005CRITICAL9.8Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-25888HIGH8.8Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-25887HIGH7.2Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-25877MEDIUM6.5Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-29093CRITICAL9.8WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memca...
CVE-2026-29046HIGH8.2TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header...
CVE-2026-29041HIGH8.8Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote co...
CVE-2026-28502HIGH8.8WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulner...
CVE-2026-28501CRITICAL9.8WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exis...
CVE-2026-28497CRITICAL9.1TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerabil...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now