2026 CVE Vulnerabilities

48,281 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-47383HIGH7.4NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated commenter could store HT...
CVE-2026-41862HIGH8.8Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-ma...
CVE-2026-23513HIGH7.1FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-constructi...
CVE-2026-12112HIGH7.8A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated ...
CVE-2026-54762HIGH8.6Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerabilit...
CVE-2026-54761HIGH7.1Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in...
CVE-2026-54555HIGH7.8rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter ...
CVE-2026-54328HIGH7.3Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension packa...
CVE-2026-39253HIGH8.1An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll a...
CVE-2026-55249HIGH8.8@rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In...
CVE-2026-54322HIGH7.7Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1...
CVE-2026-54321HIGH7Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0...
CVE-2026-54320HIGH8.4Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1...
CVE-2026-53755HIGH7.5Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF de...
CVE-2026-53754HIGH7.5Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (...
CVE-2026-54318HIGH7.1Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the...
CVE-2026-54317HIGH7.6Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the...
CVE-2026-54018HIGH7.7Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the S...
CVE-2026-54013HIGH7.6Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ...
CVE-2026-54012HIGH7.1Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ...
CVE-2026-54010HIGH8.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ...
CVE-2026-54008HIGH8.5Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backe...
CVE-2026-52845HIGH8.1Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the ...
CVE-2026-52844HIGH7.5Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat ...
CVE-2026-49440HIGH7.4Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, node:crypto.checkPrime(candidate[, options][,...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now