2026 CVE Vulnerabilities

43,669 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-68083In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix path resolution in ksmbd_vfs_kern_path_c...
CVE-2026-64941LOW2.1URL Redirection to Untrusted Site ('Open Redirect') vulnerability in phoenixframework phoenix_live_view allows an attack...
CVE-2026-59088MEDIUM5.5A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI im...
CVE-2026-72594HIGH7.6A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authentic...
CVE-2026-72593CRITICAL9.8A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to acce...
CVE-2026-72592CRITICAL9.8An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to e...
CVE-2026-72591HIGH7.7A server-side request forgery (SSRF) vulnerability in gabehf/Koito through v0.3.2 allows an authenticated user to make t...
CVE-2026-72590CRITICAL9.8An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker...
CVE-2026-72589CRITICAL9.8An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker...
CVE-2026-72588MEDIUM5.3A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to d...
CVE-2026-72587MEDIUM6.1A cache poisoning vulnerability in CoreBunch/Instatic through 0.0.14 allows an unauthenticated remote attacker to poison...
CVE-2026-72586HIGH7.5A missing authentication vulnerability in frangoteam/FUXA through 1.3.3 allows an unauthenticated remote attacker to que...
CVE-2026-72585MEDIUM6.5An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact p...
CVE-2026-72584HIGH7.4A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attac...
CVE-2026-72583MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated us...
CVE-2026-72582HIGH7.5A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to cras...
CVE-2026-72581HIGH8.6A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker...
CVE-2026-72580CRITICAL9.8An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute a...
CVE-2026-72579HIGH7.5An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept...
CVE-2026-72578HIGH8.8A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to...
CVE-2026-72577CRITICAL9.8Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary ...
CVE-2026-72576MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Autho...
CVE-2026-72575CRITICAL9.1An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read, crea...
CVE-2026-72574MEDIUM6.1A host header injection vulnerability in picocms/Pico through 2.1.4 allows an unauthenticated remote attacker to control...
CVE-2026-72573HIGH8.8An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to execut...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now