2026 CVE Vulnerabilities

48,182 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-47110HIGH7.1Tiptap for PHP before version 2.1.1 contains an input validation vulnerability that allows authenticated attackers to ca...
CVE-2026-2050HIGH7.8GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2026-10043HIGH7.8MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remot...
CVE-2026-7539HIGH7.3A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking St...
CVE-2026-52812HIGH7.1Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (<LFS...
CVE-2026-52810HIGH7.1Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git smart HTTP authorizes POST …/git-receive-pack using...
CVE-2026-52808HIGH7.1Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/...
CVE-2026-52805HIGH8.7Gogs is an open source self-hosted Git service. Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exis...
CVE-2026-52801HIGH8.1Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alter...
CVE-2026-52800HIGH8.8Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization team member management can be performed vi...
CVE-2026-52799HIGH7.5Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file ...
CVE-2026-52798HIGH8.9Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server si...
CVE-2026-52797HIGH8.5Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the valu...
CVE-2026-50129HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS c...
CVE-2026-47267HIGH8.3Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or ru...
CVE-2026-45687HIGH8.5Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ...
CVE-2026-45677HIGH8.7Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ...
CVE-2026-33235HIGH7.7AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2026-25119HIGH7.7Gogs is an open source self-hosted Git service. Prior to 0.14.3, when ENABLE_REVERSE_PROXY_AUTHENTICATION is enabled, Go...
CVE-2026-1840HIGH8.7The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication contr...
CVE-2026-13201HIGH7.3A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW...
CVE-2026-11998HIGH7.6A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and ...
CVE-2026-55583HIGH7.6Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cro...
CVE-2026-47389HIGH8.6Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when us...
CVE-2026-46348HIGH8.7Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, the lis...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now