2026 CVE Vulnerabilities

50,974 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-8775HIGH8.8A flaw has been found in Edimax BR-6428NS 1.10. This affects the function formL2TPSetup of the file /goform/formL2TPSetu...
CVE-2026-8771HIGH7.3A security flaw has been discovered in linlinjava litemall up to 1.8.0. This impacts the function list of the file litem...
CVE-2026-8768HIGH7.3A vulnerability was found in vercel ai up to 3.0.97. The affected element is the function validateDownloadUrl of the fil...
CVE-2026-8767HIGH7.5A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/pre...
CVE-2026-8764HIGH7.3A security vulnerability has been detected in H3C Magic B3 up to 100R002. This affects the function UpdateWanParams of t...
CVE-2026-46720HIGH8.2Net::Statsd::Tiny versions before 0.3.8 for Perl allowed metric injections. The metric names and set values were not ch...
CVE-2026-8759HIGH7.3A vulnerability was identified in xiandafu beetl up to 3.20.2. Affected is an unknown function of the file beetl-classic...
CVE-2026-8758HIGH7.3A vulnerability was determined in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This impacts an unknown function of the file...
CVE-2026-8756HIGH7.3A vulnerability has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The impacted elem...
CVE-2026-8755HIGH7.3A flaw has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The affected element is th...
CVE-2026-8750HIGH7.5A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file...
CVE-2026-8734HIGH7.3A vulnerability was determined in Oinone Pamirs up to 7.2.0. Affected by this issue is the function RSQLToSQLNodeConnect...
CVE-2026-8719HIGH8.8The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation...
CVE-2026-8725HIGH7.3A weakness has been identified in CoreWorxLab CAAL up to 1.6.0. The affected element is an unknown function of the file ...
CVE-2026-8724HIGH7.2A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file...
CVE-2026-46728HIGH8.8Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted fro...
CVE-2026-8657HIGH8.2Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() a...
CVE-2026-8700HIGH7.3Crypt::DSA versions before 1.20 for Perl generate seeds using rand. Seeds were generated using Perl's built-in rand fun...
CVE-2026-45665HIGH8.1Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, a Sto...
CVE-2026-45350HIGH7.1Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.6, there...
CVE-2026-45338HIGH7.7Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a Ser...
CVE-2026-45315HIGH8.7Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the a...
CVE-2026-45303HIGH7.7Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.5, throu...
CVE-2026-45301HIGH8.1Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.3.16, a mi...
CVE-2026-44570HIGH8.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, auth...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now