2026 CVE Vulnerabilities

43,494 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-72864CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the local branch of /docker-container-t...
CVE-2026-72863CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's WebSocket handlers (in-app te...
CVE-2026-71969HIGH8.4OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt a...
CVE-2026-71968MEDIUM6.7OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application lo...
CVE-2026-71967MEDIUM5.7OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pse...
CVE-2026-71964HIGH7.1CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component t...
CVE-2026-71962HIGH7.5Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants...
CVE-2026-6791MEDIUM6.6When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the ...
CVE-2026-6368LOW2.1Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return inva...
CVE-2026-68872MEDIUM6.5The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team...
CVE-2026-68871MEDIUM6.5The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id ...
CVE-2026-68870MEDIUM5.3The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Va...
CVE-2026-59091HIGH7.3A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit t...
CVE-2026-12339MEDIUM6.9A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive contai...
CVE-2026-72900HIGH7.1Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.
CVE-2026-72899CRITICAL10Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes...
CVE-2026-72898CRITICAL10Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint a...
CVE-2026-72862CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, pos...
CVE-2026-72740CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git...
CVE-2026-72739MEDIUM6.5Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs...
CVE-2026-72738CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoin...
CVE-2026-72737CRITICAL9.6Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and ...
CVE-2026-72736CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values d...
CVE-2026-72735CRITICAL9.9Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/se...
CVE-2026-72734HIGH8.4Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.28.7 until 0.29.13, the server.remove tRPC mutatio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now