2026 CVE Vulnerabilities

70,478 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28515HIGH8.8openDCIM version 23.04, through commit 4467e9c4, contains a missing authorization vulnerability in install.php and conta...
CVE-2026-28426MEDIUM5.4Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, stored XSS ...
CVE-2026-28425HIGH8Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, an authenti...
CVE-2026-28424MEDIUM6.5Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, user email ...
CVE-2026-28423HIGH8.6Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.11 and 6.4.0, when Glide ...
CVE-2026-27759MEDIUM5.3Featured Image from Content (featured-image-from-content) WordPress plugin versions prior to 1.7 contain an authenticate...
CVE-2026-28422LOW2.2Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl...
CVE-2026-28421HIGH7.8Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentati...
CVE-2026-28420MEDIUM4.4Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an ou...
CVE-2026-28419MEDIUM6.6Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim'...
CVE-2026-28418MEDIUM5.5Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds r...
CVE-2026-28417HIGH7.8Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists...
CVE-2026-28416HIGH8.6Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Fo...
CVE-2026-28415MEDIUM4.7Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, the _redirect_to_target(...
CVE-2026-28414HIGH7.5Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Win...
CVE-2026-28411CRITICAL9.8WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on...
CVE-2026-28409HIGH7.2WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulne...
CVE-2026-28408CRITICAL9.8WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.p...
CVE-2026-28407MEDIUM5.3malcontent is software for discovering supply-chain compromises through context, differential analysis, and YARA. Prior ...
CVE-2026-28406HIGH8.2kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in vers...
CVE-2026-28402HIGH7.1nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus a...
CVE-2026-28400HIGH7.5Docker Model Runner (DMR) is software used to manage, run, and deploy AI models using Docker. Versions prior to 1.0.16 e...
CVE-2026-27939HIGH8.8Statmatic is a Laravel and Git powered content management system (CMS). Starting in version 6.0.0 and prior to version 6...
CVE-2026-27167MEDIUM5.9Gradio is an open-source Python package designed for quick prototyping. Starting in version 4.16.0 and prior to version ...
CVE-2026-28355LOW1.3Canarytokens help track activity and actions on a network. Versions prior to `sha-7ff0e12` have a Self Cross-Site Script...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now