2026 CVE Vulnerabilities

50,938 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-65986HIGH8.5CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 co...
CVE-2026-54020MEDIUM6.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolv...
CVE-2026-51401HIGH7.7An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename(...
CVE-2026-51400HIGH8.4An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename(...
CVE-2026-45538CRITICAL9.8OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP mes...
CVE-2026-18813HIGH7.3A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipul...
CVE-2026-18812HIGH7.3A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Ex...
CVE-2026-18811HIGH7.3A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Perfo...
CVE-2026-13227HIGH7.1An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access co...
CVE-2026-70553CRITICAL9.8MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP...
CVE-2026-70552CRITICAL9.8MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthe...
CVE-2026-70486HIGH8.2Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the termi...
CVE-2026-70485HIGH7.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebU...
CVE-2026-70484MEDIUM4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legac...
CVE-2026-70483LOW3.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /a...
CVE-2026-70482HIGH8.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENAB...
CVE-2026-70481MEDIUM5.4Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the stand...
CVE-2026-70480MEDIUM4.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open Web...
CVE-2026-70479HIGH7.7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_...
CVE-2026-70478CRITICAL9.2Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v...
CVE-2026-70477CRITICAL9.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt inject...
CVE-2026-70476HIGH8.3Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organiz...
CVE-2026-70475HIGH7.1Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1...
CVE-2026-48154MEDIUM5.9GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions pri...
CVE-2026-47682HIGH7.1CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now