2026 CVE Vulnerabilities

43,380 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-72906MEDIUM4.3ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email ...
CVE-2026-72905Rejected reason: Further research determined the issue is not a vulnerability.
CVE-2026-72904CRITICAL9.3Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file ...
CVE-2026-72903HIGH8.1Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can retu...
CVE-2026-72743MEDIUM5.4SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashb...
CVE-2026-63622HIGH7.8A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploi...
CVE-2026-48160CRITICAL9.3react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the defau...
CVE-2026-19411LOW3.9A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could al...
CVE-2026-18982HIGH8.8A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in a...
CVE-2026-18951HIGH8.8A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly ag...
CVE-2026-18950HIGH8.8A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how Rol...
CVE-2026-18949HIGH8.8A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Ac...
CVE-2026-18948CRITICAL9.9A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, whic...
CVE-2026-18947HIGH8.5A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental...
CVE-2026-18942MEDIUM5.5A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. Th...
CVE-2026-18941HIGH7.7A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is...
CVE-2026-18621HIGH7.6A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security harde...
CVE-2026-18620HIGH7.1A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerab...
CVE-2026-18618HIGH7.5A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to kn...
CVE-2026-18617HIGH8.8A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the sp...
CVE-2026-18611HIGH7.5A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive...
CVE-2026-18608HIGH8.7A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permission...
CVE-2026-16456MEDIUM6.5A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can ex...
CVE-2026-15581HIGH8A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to b...
CVE-2026-15467HIGH8.1A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can e...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now