2026 CVE Vulnerabilities

56,979 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45804HIGH7.5Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, Diffusers' DiffusionPipeline.from_pretraine...
CVE-2026-45793HIGH7.5Composer is a dependency Manager for the PHP language. Prior to 1.10.28, 2.2.28, and 2.9.8, Composer\IO\BaseIO::loadConf...
CVE-2026-20187HIGH7.5As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c...
CVE-2026-20158HIGH7.5As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c...
CVE-2026-20157CRITICAL9.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c...
CVE-2026-20156CRITICAL9.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c...
CVE-2026-20153HIGH7.5As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c...
CVE-2026-20150HIGH8.8As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has c...
CVE-2026-20146MEDIUM5.5A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a...
CVE-2026-1563MEDIUM4.8Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a u...
CVE-2026-1562MEDIUM4.8Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user...
CVE-2026-9007MEDIUM5.5Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL...
CVE-2026-62843MEDIUM6.8File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-62685HIGH8.1File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-62683LOW3.1File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec...
CVE-2026-61828HIGH8.5Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and ...
CVE-2026-61605Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-58655. Reason: This candidate is a ...
CVE-2026-61371HIGH7.5Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/...
CVE-2026-60005HIGH8.2NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and ...
CVE-2026-55242HIGH8.8ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated use...
CVE-2026-50148CRITICAL9.1Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.2...
CVE-2026-50147HIGH7.6Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1....
CVE-2026-47164HIGH7.7Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the ...
CVE-2026-47160MEDIUM5.8Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png en...
CVE-2026-47159MEDIUM6.9Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-valid...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now