2026 CVE Vulnerabilities

47,201 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-53644HIGH8.6FOSSBilling is a free, open-source billing and client management system. Versions 0.5.3 through 0.7.2 allow authenticate...
CVE-2026-53643HIGH8.7FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged st...
CVE-2026-43921HIGH8.9FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code i...
CVE-2026-43918HIGH8.7FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/...
CVE-2026-42204HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 ...
CVE-2026-42153HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-38976HIGH7.5mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missi...
CVE-2026-34599HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-34153HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-59713HIGH8.6Leantime contains an OIDC login CSRF vulnerability in the verifyState() method that unconditionally returns true without...
CVE-2026-59712HIGH8.6Leantime's Users::getUser method in the JSON-RPC API lacks proper authorization checks, allowing authenticated users to ...
CVE-2026-57573HIGH8.6Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF ...
CVE-2026-55727HIGH7.5A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14...
CVE-2026-55574HIGH7.5vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_ou...
CVE-2026-54765HIGH8.5Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gatewa...
CVE-2026-54234HIGH7.5vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, a frontend-legal ...
CVE-2026-42331HIGH7.7FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/u...
CVE-2026-25271HIGH7Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between chec...
CVE-2026-25268HIGH8.8Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
CVE-2026-21383HIGH7.1Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value fo...
CVE-2026-21379HIGH7.8Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.
CVE-2026-14471HIGH8.6Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-g...
CVE-2026-14468HIGH7.7HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that...
CVE-2026-14536HIGH8.8Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attack...
CVE-2026-9181HIGH7.5Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An una...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now