2026 CVE Vulnerabilities

56,979 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-47158HIGH8.3Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did ...
CVE-2026-46709HIGH7.8Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths...
CVE-2026-45806HIGH7.7Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import pa...
CVE-2026-45805HIGH8.8Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/serve...
CVE-2026-45150MEDIUM6.3Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security no...
CVE-2026-44986CRITICAL9.9Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitation...
CVE-2026-41580MEDIUM6.1Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, Stirl...
CVE-2026-62294MEDIUM5.1Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to...
CVE-2026-61836HIGH8.6Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching ...
CVE-2026-61835HIGH7.7Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on...
CVE-2026-61740CRITICAL9.3LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRA...
CVE-2026-61736CRITICAL9.3LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* ...
CVE-2026-61684HIGH8.8FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints unde...
CVE-2026-61646MEDIUM6.3FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta5, FastGPT's shared SSRF guard validates only ...
CVE-2026-61644HIGH7.7FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api/core/chat/record/ge...
CVE-2026-61613HIGH7.7Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Curso...
CVE-2026-60065MEDIUM5.3When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filte...
CVE-2026-60062MEDIUM6.4The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files ou...
CVE-2026-59762HIGH8.7When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource ...
CVE-2026-56434HIGH8.3NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist wh...
CVE-2026-55723HIGH8.7When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection...
CVE-2026-54563HIGH7.1Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a c...
CVE-2026-54562MEDIUM6.5Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow acc...
CVE-2026-54560HIGH7.6Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens...
CVE-2026-52865HIGH7.1When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with per...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now