2026 CVE Vulnerabilities

48,558 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-71311MEDIUM6.4rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1...
CVE-2026-71310MEDIUM5.9rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1...
CVE-2026-71309HIGH8.6rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40....
CVE-2026-34966HIGH8.3Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass...
CVE-2026-18959MEDIUM5.4A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::des...
CVE-2026-18839LOW2.2An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal ...
CVE-2026-18411HIGH8.1The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication k...
CVE-2026-17583HIGH8.4The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be ed...
CVE-2026-15996HIGH7.5A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to...
CVE-2026-70618MEDIUM5.3Spacebar Server before commit 51da17c contains a missing authorization vulnerability that allows any authenticated user ...
CVE-2026-70617HIGH8.6Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attac...
CVE-2026-70616HIGH7.1boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanentl...
CVE-2026-70615CRITICAL9.9boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users wit...
CVE-2026-69111HIGH8.7Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers...
CVE-2026-68746HIGH8.8Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to...
CVE-2026-66885MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's b...
CVE-2026-66881HIGH8.1Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with...
CVE-2026-66298HIGH8.8Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger se...
CVE-2026-66297HIGH8Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev l...
CVE-2026-55524HIGH7.5PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on...
CVE-2026-55523HIGH7.7PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.w...
CVE-2026-55522HIGH7.8PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of p...
CVE-2026-21766MEDIUM5.4The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. ...
CVE-2026-18958HIGH7.3A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a...
CVE-2026-18954MEDIUM5.7Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might al...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now