2026 CVE Vulnerabilities

51,117 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-42271HIGH8.8LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before vers...
CVE-2026-42261HIGH7.1PromptHub is an all-in-one AI toolbox for prompt, skill, and agent management. From version 0.4.9 to before version 0.5....
CVE-2026-42203HIGH8.8LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before vers...
CVE-2026-8128HIGH7.3A vulnerability was found in SourceCodester SUP Online Shopping 1.0. The affected element is an unknown function of the ...
CVE-2026-8126HIGH7.3A flaw has been found in SourceCodester Comment System 1.0. This issue affects some unknown processing of the file post_...
CVE-2026-6411HIGH7.3This vulnerability, in the MAXHUB Pivot client application versions prior to v1.36.2, may allow an attacker to obtain e...
CVE-2026-8112HIGH8.8A vulnerability was found in 8421bit MiniClaw up to 223c16a1088e138838dcbd18cd65a37c35ac5a84. Affected is the function e...
CVE-2026-7541HIGH7.5A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to...
CVE-2026-42826HIGH7.5Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose i...
CVE-2026-41105HIGH8.1Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges ove...
CVE-2026-40213HIGH7.4OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This un...
CVE-2026-34327HIGH8.2Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attac...
CVE-2026-33111HIGH7.5Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) all...
CVE-2026-26164HIGH7.5Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...
CVE-2026-26129HIGH7.5Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz...
CVE-2026-8098HIGH7.3A security vulnerability has been detected in code-projects Feedback System 1.0. Impacted is an unknown function of the ...
CVE-2026-42449HIGH8.5n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In ve...
CVE-2026-42047HIGH8.6Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orche...
CVE-2026-8087HIGH7.8A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frm...
CVE-2026-42501HIGH7.5A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa...
CVE-2026-42499HIGH7.5Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
CVE-2026-42239HIGH8.1Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT sess...
CVE-2026-39836HIGH7.5The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0).
CVE-2026-39820HIGH7.5Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion...
CVE-2026-33814HIGH7.5When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now