2026 CVE Vulnerabilities

43,380 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-69112HIGH7.1Hugging Face Accelerate through 1.14.0 contains a path traversal vulnerability in load_checkpoint_in_model and load_chec...
CVE-2026-44401MEDIUM4.8Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that ...
CVE-2026-14886HIGH8.2Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that ma...
CVE-2026-72872CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.saveBitbucketProvider store...
CVE-2026-72871HIGH7.5Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the unauthenticated /api/providers/gith...
CVE-2026-72870HIGH8.7Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in pac...
CVE-2026-72869CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC s...
CVE-2026-72868CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, apps/dokploy/server/api/routers/destina...
CVE-2026-72867CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.3 until 0.29.13, the incomplete fix for CVE-202...
CVE-2026-72866HIGH8.8Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the WebSocket handler in apps/dokploy/s...
CVE-2026-72865CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the compose.update operation stores an ...
CVE-2026-72864CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-t...
CVE-2026-72863CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app te...
CVE-2026-71969HIGH8.4OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt a...
CVE-2026-71968MEDIUM6.7OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application lo...
CVE-2026-71967MEDIUM5.7OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pse...
CVE-2026-71964HIGH7.1CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component t...
CVE-2026-71962HIGH7.5Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants...
CVE-2026-6791MEDIUM6.6When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the ...
CVE-2026-6368LOW2.1Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return inva...
CVE-2026-68872MEDIUM6.5The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team...
CVE-2026-68871MEDIUM6.5The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id ...
CVE-2026-68870MEDIUM5.3The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Va...
CVE-2026-59091HIGH7.3A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit t...
CVE-2026-12339MEDIUM6.9A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive contai...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now