2026 CVE Vulnerabilities

48,561 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6667MEDIUM4.3PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users ...
CVE-2026-45130MEDIUM5.5Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compou...
CVE-2026-44656MEDIUM5.3Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists...
CVE-2026-44284MEDIUM6.3FastGPT is an AI Agent building platform. Prior to version 4.14.17, FastGPT had an inconsistent SSRF protection gap in M...
CVE-2026-42456MEDIUM4.3AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti...
CVE-2026-42451MEDIUM6.3Grimmory is a self-hosted digital library. Prior to version 2.3.1, a stored cross-site scripting (XSS) vulnerability in ...
CVE-2026-42350MEDIUM5.1Kargo manages and automates the promotion of software artifacts. Prior to versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2, Ka...
CVE-2026-42346MEDIUM6.5Postiz is an AI social media scheduling tool. From version 2.16.6 to before version 2.21.7, all SSRF protections added i...
CVE-2026-42344MEDIUM6.3FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packa...
CVE-2026-42343MEDIUM6.3FastGPT is an AI Agent building platform. In versions 4.14.13 and prior, the code-sandbox component suffers from insuffi...
CVE-2026-42307MEDIUM4.4Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists...
CVE-2026-42291MEDIUM6.8SysReptor is a fully customizable pentest reporting platform. From version 2026.4 to before version 2026.27, the endpoin...
CVE-2026-41682MEDIUM6.9pupnp is an SDK for development of UPnP device and control point applications. Prior to version 1.18.5, pupnp is vulnera...
CVE-2026-41520MEDIUM4.4Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1....
CVE-2026-42213MEDIUM5.1SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0....
CVE-2026-42209MEDIUM6.5FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.1, a remote client with reta...
CVE-2026-42206MEDIUM5.7Roadiz is a polymorphic content management system based on a node system. Prior to versions 2.3.43, 2.5.45, 2.6.31, and ...
CVE-2026-42202MEDIUM6.5nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-...
CVE-2026-42199MEDIUM6.2Grid is a data structure grid for rust. From version 0.17.0 to before version 1.0.1, an integer overflow in Grid::expand...
CVE-2026-42192MEDIUM5.4Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (X...
CVE-2026-42282MEDIUM4.3n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-42190MEDIUM5.3RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to before version 1.2.3, server actions in rwsd...
CVE-2026-42185MEDIUM5.5People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0,...
CVE-2026-42181MEDIUM6.5Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy fetches metadata for user-suppli...
CVE-2026-42180MEDIUM6.3Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy allows an authenticated low-priv...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now