2026 CVE Vulnerabilities

48,030 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-48042HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-47221HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.18.0 until 1.35.13, 1.36.9...
CVE-2026-47204HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9...
CVE-2026-57518HIGH8.8Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage ...
CVE-2026-57231HIGH7.5Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environ...
CVE-2026-56663HIGH8.5AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-55677HIGH7.5Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decodi...
CVE-2026-45406HIGH8.8Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-i...
CVE-2026-45405HIGH8.8Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/z...
CVE-2026-9640HIGH7.2A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 reg...
CVE-2026-5757HIGH7.5Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to ...
CVE-2026-47214HIGH7.1Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos...
CVE-2026-45195HIGH7.8Kernel software installed and running inside a Host VM may post improper commands to the GPU Firmware to trigger a memor...
CVE-2026-44018HIGH7.1Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecos...
CVE-2026-21734HIGH7.7A web page that contains unusual GPU shader code is loaded into the GPU compiler process and can trigger a write out-of-...
CVE-2026-0828HIGH7.5Kernel driver ProcessMonitorDriver.sys in Safetica's endpoint client x64 , versions 10.5.75.0 and 11.11.4.0, allows unpr...
CVE-2026-57667HIGH8.5Sales Representative SQL Injection in Groundhogg <= 4.5 versions.
CVE-2026-57663HIGH8.5Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.
CVE-2026-57662HIGH8.5Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.
CVE-2026-57659HIGH8.8Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions.
CVE-2026-57655HIGH8.2Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard <= 1.4 versions.
CVE-2026-57653HIGH8.5Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.
CVE-2026-57647HIGH7.5Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions.
CVE-2026-57645HIGH8.1newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
CVE-2026-57644HIGH8.5Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now