2026 CVE Vulnerabilities

55,551 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48013MEDIUM4.1Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint ...
CVE-2026-48012MEDIUM4.3Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO ...
CVE-2026-47722HIGH8.7nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `inter...
CVE-2026-47670CRITICAL9.4DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Executio...
CVE-2026-47669CRITICAL9.3DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api...
CVE-2026-25800HIGH7.5Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and...
CVE-2026-15212HIGH8.8The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43...
CVE-2026-12353MEDIUM5.3An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly se...
CVE-2026-65010MEDIUM6.6Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that a...
CVE-2026-63765HIGH8.8Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unau...
CVE-2026-16756HIGH8.7Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path o...
CVE-2026-15687LOW2.4A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new ...
CVE-2026-6516CRITICAL10Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the...
CVE-2026-65920MEDIUM5.3Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_...
CVE-2026-65919HIGH8.7Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api...
CVE-2026-65918HIGH7.1PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GI...
CVE-2026-65763MEDIUM5.1Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs...
CVE-2026-65762MEDIUM5.1Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user i...
CVE-2026-65702HIGH8.6Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration t...
CVE-2026-65701CRITICAL9.3SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inf...
CVE-2026-65700CRITICAL9.8h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthentica...
CVE-2026-65699MEDIUM4.2AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authentica...
CVE-2026-47769MEDIUM5.3APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Pr...
CVE-2026-47755MEDIUM6.5ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi...
CVE-2026-47752CRITICAL9.9Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to S...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now