2026 CVE Vulnerabilities

51,085 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-41705HIGH8.6Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized...
CVE-2026-42455HIGH8.8Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In ve...
CVE-2026-42453HIGH8.7Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v...
CVE-2026-42452HIGH8.1Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v...
CVE-2026-42352HIGH8.6pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23...
CVE-2026-42351HIGH7.5pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23...
CVE-2026-42345HIGH7.7FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packa...
CVE-2026-42339HIGH7.1New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.1...
CVE-2026-42224HIGH7.6ipl/web is a set of common web components for php projects. Prior to versions 0.13.1 and 0.10.3, the vulnerability allow...
CVE-2026-41432HIGH8.2New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio...
CVE-2026-42286HIGH8.4Emlog is an open source website building system. Prior to version 2.6.11, missing CSRF protection in critical admin func...
CVE-2026-42212HIGH7.1SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0....
CVE-2026-42205HIGH8.8Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulne...
CVE-2026-41486HIGH8.8Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension typ...
CVE-2026-7807HIGH8.8SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary...
CVE-2026-42189HIGH7.5Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerabili...
CVE-2026-29203HIGH8.8A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on ...
CVE-2026-29202HIGH8.8Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution...
CVE-2026-29201HIGH8.6Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary f...
CVE-2026-6659HIGH7.5Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function ...
CVE-2026-44499HIGH8.7ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Z...
CVE-2026-43967HIGH7.5Inefficient Algorithmic Complexity vulnerability in absinthe-graphql absinthe allows unauthenticated denial of service v...
CVE-2026-42793HIGH7.5Allocation of Resources Without Limits or Throttling vulnerability in absinthe-graphql absinthe allows unauthenticated d...
CVE-2026-42353HIGH8.2i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno...
CVE-2026-41886HIGH7.5locize is a localization platform that connects code and i18n setup. Prior to version 4.0.21, the locize client SDK regi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now