2026 CVE Vulnerabilities

53,393 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-65010MEDIUM6.6Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that a...
CVE-2026-63765HIGH8.8Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unau...
CVE-2026-16756HIGH8.7Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path o...
CVE-2026-15687LOW2.4A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new ...
CVE-2026-6516CRITICAL10Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the...
CVE-2026-65920MEDIUM5.3Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_...
CVE-2026-65919HIGH8.7Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api...
CVE-2026-65918HIGH7.1PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GI...
CVE-2026-65763MEDIUM5.1Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs...
CVE-2026-65762MEDIUM5.1Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user i...
CVE-2026-65702HIGH8.6Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration t...
CVE-2026-65701CRITICAL9.3SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inf...
CVE-2026-65700CRITICAL9.8h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthentica...
CVE-2026-65699MEDIUM4.2AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authentica...
CVE-2026-47769MEDIUM5.3APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Pr...
CVE-2026-47755MEDIUM6.5ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi...
CVE-2026-47752CRITICAL9.9Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to S...
CVE-2026-47743HIGH8.7Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed...
CVE-2026-47668CRITICAL10DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/star...
CVE-2026-44210CRITICAL9.9Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...
CVE-2026-65761CRITICAL9.3Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validat...
CVE-2026-65760CRITICAL9.2Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0...
CVE-2026-65759HIGH8.7Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical...
CVE-2026-65698MEDIUM6Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjace...
CVE-2026-65697MEDIUM6.1Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now