2026 CVE Vulnerabilities

43,380 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-72900HIGH7.1Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.
CVE-2026-72899CRITICAL10Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes...
CVE-2026-72898CRITICAL10Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint a...
CVE-2026-72862CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, pos...
CVE-2026-72740CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git...
CVE-2026-72739MEDIUM6.5Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs...
CVE-2026-72738CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoin...
CVE-2026-72737CRITICAL9.6Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and ...
CVE-2026-72736CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values d...
CVE-2026-72735CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/se...
CVE-2026-72734HIGH8.4Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutatio...
CVE-2026-72733CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC s...
CVE-2026-72732MEDIUM4.3Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse_temp...
CVE-2026-70622HIGH7.1tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function t...
CVE-2026-48159CRITICAL9.3use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the def...
CVE-2026-16626CRITICAL9.3Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server...
CVE-2026-10754HIGH8.6Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may ...
CVE-2026-72731HIGH7.1Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-l...
CVE-2026-72730HIGH8.7Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Edit...
CVE-2026-72729LOW2Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the discourse-loca...
CVE-2026-72728MEDIUM6.3Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed ...
CVE-2026-72727MEDIUM4.8Discourse is an open-source discussion platform. Prior to 026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, a low-privileged us...
CVE-2026-71577MEDIUM6.3A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed...
CVE-2026-71576HIGH8.5A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming ...
CVE-2026-63623MEDIUM5.5A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were tempora...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now