2026 CVE Vulnerabilities

53,348 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-33735HIGH8.8MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypas...
CVE-2026-33725HIGH7.2Metabase is an open source business intelligence and embedded analytics tool. In Metabase Enterprise prior to versions 1...
CVE-2026-33721HIGH7.5MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a h...
CVE-2026-33699HIGH7.5pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.2 have a vulnerability in which an attack...
CVE-2026-4905HIGH8.8A vulnerability was found in Tenda AC5 15.03.06.47. Impacted is the function formWifiWpsOOB of the file /goform/WifiWpsO...
CVE-2026-4904HIGH8.8A vulnerability has been found in Tenda AC5 15.03.06.47. This issue affects the function formSetCfm of the file /goform/...
CVE-2026-33898HIGH8.8Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui...
CVE-2026-29070HIGH8.1Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8....
CVE-2026-28788HIGH7.1Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.8....
CVE-2026-27893HIGH8.8vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to versio...
CVE-2026-4903HIGH8.8A flaw has been found in Tenda AC5 15.03.06.47. This vulnerability affects the function formQuickIndex of the file /gofo...
CVE-2026-4902HIGH8.8A vulnerability was detected in Tenda AC5 15.03.06.47. This affects the function fromAddressNat of the file /goform/addr...
CVE-2026-33711HIGH7.8Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API reli...
CVE-2026-3650HIGH8.7A memory leak exists in the Grassroots DICOM library (GDCM). The bug occurs when parsing malformed DICOM files with non-...
CVE-2026-33687HIGH8.8Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 contain a vulnerability...
CVE-2026-33686HIGH8.8Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal v...
CVE-2026-33671HIGH7.5Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expr...
CVE-2026-33670HIGH7.5SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to tr...
CVE-2026-33669HIGH7.5SiYuan is a personal knowledge management system. Prior to version 3.6.2, document IDs were retrieved via the /api/file/...
CVE-2026-33661HIGH7.5Pay is an open-source payment SDK extension package for various Chinese payment services. Prior to version 3.7.20, the `...
CVE-2026-28377HIGH7.5A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, p...
CVE-2026-4933HIGH7.5Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions allows Forceful Browsing.This issue affects...
CVE-2026-3622HIGH7.5The vulnerability exists in the UPnP component of TL-WR841N v14, where improper input validation leads to an out-of-boun...
CVE-2026-3573HIGH7.5Incorrect Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Resource Injection.This issue affect...
CVE-2026-33645HIGH8.1Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerabilit...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now