2026 CVE Vulnerabilities

51,945 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-67595CRITICAL9.2VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template re...
CVE-2026-18060Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-15157MEDIUM5.4undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type he...
CVE-2026-14643HIGH7.5undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or priva...
CVE-2026-67439MEDIUM4.3OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service...
CVE-2026-67438MEDIUM6.6OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/inte...
CVE-2026-67437HIGH7.5OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/inte...
CVE-2026-65975MEDIUM6.5Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 u...
CVE-2026-54249MEDIUM6.8Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and...
CVE-2026-50782HIGH7.5Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manage...
CVE-2026-46678MEDIUM5.9Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when...
CVE-2026-16728MEDIUM6.5undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to ...
CVE-2026-13309MEDIUM6.8Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerabili...
CVE-2026-13308HIGH8.1Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability all...
CVE-2026-13307MEDIUM6.8Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerabilit...
CVE-2026-13306MEDIUM4.3Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability. This vulnerability allows physically present at...
CVE-2026-13305MEDIUM6.4Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Executio...
CVE-2026-6336MEDIUM5.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 1...
CVE-2026-6267MEDIUM5.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and...
CVE-2026-6102HIGH7.8MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local...
CVE-2026-67436HIGH8.3Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In...
CVE-2026-67435MEDIUM6linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to ve...
CVE-2026-67433MEDIUM5.8Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In...
CVE-2026-67432HIGH7.5MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Tran...
CVE-2026-67431HIGH8.3MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Tran...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now