2026 CVE Vulnerabilities
48,281 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47383 | HIGH | 7.4 | 0.3% | Jun 23, 2026 | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, an authenticated commenter could store HT... |
| CVE-2026-41862 | HIGH | 8.8 | 0.4% | Jun 23, 2026 | Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-ma... |
| CVE-2026-23513 | HIGH | 7.1 | 0.3% | Jun 23, 2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-constructi... |
| CVE-2026-12112 | HIGH | 7.8 | 0.2% | Jun 23, 2026 | A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated ... |
| CVE-2026-54762 | HIGH | 8.6 | 0.2% | Jun 23, 2026 | Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerabilit... |
| CVE-2026-54761 | HIGH | 7.1 | 0.4% | Jun 23, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in... |
| CVE-2026-54555 | HIGH | 7.8 | 0.1% | Jun 23, 2026 | rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter ... |
| CVE-2026-54328 | HIGH | 7.3 | 0.1% | Jun 23, 2026 | Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension packa... |
| CVE-2026-39253 | HIGH | 8.1 | 0.8% | Jun 23, 2026 | An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll a... |
| CVE-2026-55249 | HIGH | 8.8 | 0.2% | Jun 23, 2026 | @rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In... |
| CVE-2026-54322 | HIGH | 7.7 | 0.2% | Jun 23, 2026 | Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1... |
| CVE-2026-54321 | HIGH | 7 | 0.2% | Jun 23, 2026 | Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0... |
| CVE-2026-54320 | HIGH | 8.4 | 0.2% | Jun 23, 2026 | Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.1... |
| CVE-2026-53755 | HIGH | 7.5 | 0.3% | Jun 23, 2026 | Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF de... |
| CVE-2026-53754 | HIGH | 7.5 | 0.3% | Jun 23, 2026 | Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (... |
| CVE-2026-54318 | HIGH | 7.1 | 0.1% | Jun 23, 2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the... |
| CVE-2026-54317 | HIGH | 7.6 | 0.2% | Jun 23, 2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the... |
| CVE-2026-54018 | HIGH | 7.7 | 0.3% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the S... |
| CVE-2026-54013 | HIGH | 7.6 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ... |
| CVE-2026-54012 | HIGH | 7.1 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ... |
| CVE-2026-54010 | HIGH | 8.3 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ... |
| CVE-2026-54008 | HIGH | 8.5 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backe... |
| CVE-2026-52845 | HIGH | 8.1 | 0.2% | Jun 23, 2026 | Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the ... |
| CVE-2026-52844 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat ... |
| CVE-2026-49440 | HIGH | 7.4 | 0.1% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, node:crypto.checkPrime(candidate[, options][,... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now