2026 CVE Vulnerabilities

64,704 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-100681MEDIUM5.4Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability...
CVE-2026-100678MEDIUM6.5stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who kn...
CVE-2026-100677MEDIUM5.3stoatchat before 0.15.5 contains an account enumeration vulnerability in the login endpoint that exposes source file loc...
CVE-2026-100675MEDIUM6.5stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that processes ...
CVE-2026-100674MEDIUM4.3stoatchat before 0.15.5 fails to revalidate usernames after Unicode sanitization, allowing attackers to create usernames...
CVE-2026-100668MEDIUM6.5Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) is...
CVE-2026-100667MEDIUM5.3grav-plugin-login (the Grav CMS Login plugin) versions >= 3.8.7 and < 3.9.7 allow the two-factor authentication challeng...
CVE-2026-100659MEDIUM6.5Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC ...
CVE-2026-100658MEDIUM5.3Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue in WebSocketServerExtensionHandler. The han...
CVE-2026-100654MEDIUM6.5vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/cha...
CVE-2026-100653MEDIUM6.5vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-...
CVE-2026-100652MEDIUM5.9vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC fron...
CVE-2026-100651MEDIUM6.5vLLM before 0.29.0 fails to enforce decoder prompt-length validation on the disaggregated serving endpoint /inference/v1...
CVE-2026-100650MEDIUM6.5vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls...
CVE-2026-100648MEDIUM5.3vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing un...
CVE-2026-100647MEDIUM5.3vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-com...
CVE-2026-100640MEDIUM4.7SiYuan before v3.8.4 contains an authorization omission in the siyuan-get IPC handler that allows remote-kernel renderer...
CVE-2026-100635MEDIUM5.9SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are is...
CVE-2026-100634MEDIUM4.7SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the...
CVE-2026-100633MEDIUM6.5SiYuan is a self-hosted personal knowledge management system. In versions 3.8.0 through 3.8.3, the MCP file tool's sensi...
CVE-2026-100632MEDIUM6.5Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, Live...
CVE-2026-100630MEDIUM5.4AVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an i...
CVE-2026-100629MEDIUM5.5Capgo (capgo.app backend) before 12.127.5 contains an authorization flaw in the PATCH /private/role_bindings/:binding_id...
CVE-2026-100628MEDIUM4.3capgo.app before 12.128.12 fails to enforce an organization's API key expiration policy when creating app-scoped API key...
CVE-2026-100626MEDIUM4.3capgo through 12.128.2 contains an insecure direct object reference vulnerability in the PUT /app/:appId endpoint that a...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now