2026 CVE Vulnerabilities

55,810 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-65763MEDIUM5.1Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs...
CVE-2026-65762MEDIUM5.1Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user i...
CVE-2026-65702HIGH8.6Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration t...
CVE-2026-65701CRITICAL9.3SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inf...
CVE-2026-65700CRITICAL9.8h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthentica...
CVE-2026-65699MEDIUM4.2AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authentica...
CVE-2026-47769MEDIUM5.3APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Pr...
CVE-2026-47755MEDIUM6.5ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi...
CVE-2026-47752CRITICAL9.9Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to S...
CVE-2026-47743HIGH8.7Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed...
CVE-2026-47668CRITICAL10DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/star...
CVE-2026-44210CRITICAL9.9Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...
CVE-2026-65761CRITICAL9.3Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validat...
CVE-2026-65760CRITICAL9.2Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0...
CVE-2026-65759HIGH8.7Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical...
CVE-2026-65698MEDIUM6Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjace...
CVE-2026-65697MEDIUM6.1Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that...
CVE-2026-65696MEDIUM5.4Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscrip...
CVE-2026-65695HIGH7.6Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attacker...
CVE-2026-44909HIGH7.5Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticate...
CVE-2026-16768MEDIUM5.3A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined pale...
CVE-2026-65917HIGH8.8CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in ...
CVE-2026-65916HIGH8.1CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCre...
CVE-2026-48539MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report conf...
CVE-2026-48538MEDIUM5.4GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configurat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now