2026 CVE Vulnerabilities

43,896 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-40079CRITICAL9.8Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command ...
CVE-2026-39955CRITICAL9.8Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQ...
CVE-2026-39948CRITICAL9.8Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request pa...
CVE-2026-39938CRITICAL9.8Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI t...
CVE-2026-55666CRITICAL9.3Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, ...
CVE-2026-55570CRITICAL9SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (...
CVE-2026-55455CRITICAL9.1Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filte...
CVE-2026-55454CRITICAL9.9Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-pr...
CVE-2026-54158CRITICAL9.9SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell render...
CVE-2026-54069CRITICAL9.2SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan Note's kernel HTTP server uncondit...
CVE-2026-54067CRITICAL9.9SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> brea...
CVE-2026-50551CRITICAL9.9SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scrip...
CVE-2026-39893CRITICAL9.8Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request va...
CVE-2026-52813CRITICAL10Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences ...
CVE-2026-52811CRITICAL9Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only ...
CVE-2026-52806CRITICAL9.9Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code ...
CVE-2026-46423CRITICAL9.3Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ...
CVE-2026-45689CRITICAL9.1Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ...
CVE-2026-45688CRITICAL9.1Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ...
CVE-2026-33543CRITICAL9.3FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API end...
CVE-2026-53943CRITICAL9.6Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that resul...
CVE-2026-49980CRITICAL9.8Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46....
CVE-2026-13032CRITICAL9.6Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially per...
CVE-2026-13028CRITICAL9.6Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially per...
CVE-2026-54906CRITICAL9.8concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock doe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now