2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-18611HIGH7.5A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive...
CVE-2026-18608HIGH8.7A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permission...
CVE-2026-15581HIGH8A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to b...
CVE-2026-15467HIGH8.1A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can e...
CVE-2026-13717HIGH8.8A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serv...
CVE-2026-11810HIGH7.5The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) pars...
CVE-2026-72884HIGH8.7Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, sanitizeCommand in packages/server/src/...
CVE-2026-72883HIGH8.8Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handlers in apps/dokploy/...
CVE-2026-72875HIGH8.8Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, settings.readTraefikFile in apps/dokplo...
CVE-2026-72874HIGH8.7Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, cloneGitRepository in packages/server/s...
CVE-2026-71966HIGH8.8CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backu...
CVE-2026-71965HIGH8.8CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote b...
CVE-2026-69118HIGH8.8Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows ...
CVE-2026-69114HIGH7.1Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and b...
CVE-2026-69112HIGH7.1Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_chec...
CVE-2026-14886HIGH8.2Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that ma...
CVE-2026-72871HIGH7.5Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/gith...
CVE-2026-72870HIGH8.7Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in pac...
CVE-2026-72866HIGH8.8Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/s...
CVE-2026-71969HIGH8.4OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt a...
CVE-2026-71964HIGH7.1CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component t...
CVE-2026-71962HIGH7.5Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants...
CVE-2026-59091HIGH7.3A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit t...
CVE-2026-72900HIGH7.1Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.
CVE-2026-72734HIGH8.4Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutatio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now