2026 CVE Vulnerabilities

49,799 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-33590HIGH8.5Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access a...
CVE-2026-33462HIGH7.3A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with...
CVE-2026-32847HIGH8.7DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/mai...
CVE-2026-4944HIGH8.8vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in t...
CVE-2026-47333HIGH7.8Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an i...
CVE-2026-47331HIGH7.8Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivile...
CVE-2026-46509HIGH8.2deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, prototype pollution is possible when prope...
CVE-2026-45332HIGH7.5Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Acce...
CVE-2026-45044HIGH8.8RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelis...
CVE-2026-45042HIGH7.1RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper authorization in the Upload...
CVE-2026-45041HIGH8.7RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, crates/appauth/src/token.rs ships a ...
CVE-2026-44394HIGH8.1An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not p...
CVE-2026-43000HIGH8.8An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation ...
CVE-2026-42999HIGH8.8An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditi...
CVE-2026-42998HIGH8.8An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin d...
CVE-2026-30761HIGH7.3An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6...
CVE-2026-30760HIGH7.3An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the...
CVE-2026-45373HIGH7.4CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, although SSRF is validated against hostnames t...
CVE-2026-45353HIGH7.8electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vul...
CVE-2026-45348HIGH8.7pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template a...
CVE-2026-45310HIGH7.4CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validates the initial URL's...
CVE-2026-45296HIGH7.7OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's Python API exposes several app_apikey ro...
CVE-2026-44798HIGH7.1Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, a user with access to ...
CVE-2026-44797HIGH8.5Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot's Webhook dat...
CVE-2026-34126HIGH7.5TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now