2026 CVE Vulnerabilities

53,348 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-4953HIGH7.3A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/...
CVE-2026-33757HIGH8.3OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for ...
CVE-2026-33755HIGH8.8Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, a...
CVE-2026-33750HIGH7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to versions 5.0.5, ...
CVE-2026-33748HIGH7.5BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P...
CVE-2026-33433HIGH8.8Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.42, 3.6.11, and 3.7.0-ea.3, when `headerField...
CVE-2026-30637HIGH7.5Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and b...
CVE-2026-29871HIGH7.5A path traversal vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251...
CVE-2026-27880HIGH7.5The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory cra...
CVE-2026-27877HIGH7.5When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being u...
CVE-2026-32695HIGH7.7Traefik is an HTTP reverse proxy and load balancer. Prior to versions 3.6.11 and 3.7.0-ea.2, Traefik's Knative provider ...
CVE-2026-4982HIGH7.3A user with permission "update world" in any Venueless world is able to exfiltrate chat messages from direct messages or...
CVE-2026-25099HIGH8.8Bludit’s API plugin allows an authenticated attacker with a valid API token to upload files of any type and extension wi...
CVE-2026-27858HIGH7.5Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount ...
CVE-2026-27857HIGH7.5Sending "NOOP (((...)))" command with 4000 parenthesis open+close results in ~1MB extra memory usage. Longer commands wi...
CVE-2026-24031HIGH8.2Dovecot SQL based authentication can be bypassed when auth_username_chars is cleared by admin. This vulnerability allows...
CVE-2026-32678HIGH8.7Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical confi...
CVE-2026-22744HIGH7.5In RedisFilterExpressionConverter of spring-ai-redis-store, when a user-controlled string is passed as a filter value fo...
CVE-2026-22743HIGH7.5Spring AI's spring-ai-neo4j-store contains a Cypher injection vulnerability in Neo4jVectorFilterExpressionConverter. Whe...
CVE-2026-22742HIGH8.6Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatMo...
CVE-2026-4910HIGH7.3A security vulnerability has been detected in Shenzhen Ruiming Technology Streamax Crocus up to 1.3.44. Affected is an u...
CVE-2026-4906HIGH8.8A vulnerability was determined in Tenda AC5 15.03.06.47. The affected element is the function decodePwd of the file /gof...
CVE-2026-33935HIGH7.5MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated att...
CVE-2026-33745HIGH7.4cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.39.0, the cpp-httplib HTTP ...
CVE-2026-33744HIGH7.8BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now