2026 CVE Vulnerabilities

57,011 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-57363HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatB...
CVE-2026-49876MEDIUM6.5Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpo...
CVE-2026-41041CRITICAL9.1URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache...
CVE-2026-22103CRITICAL9.3The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.
CVE-2026-22102CRITICAL9.3A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint acce...
CVE-2026-22100HIGH8.6The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitra...
CVE-2026-22099HIGH8.7The charging station does not require authentication for Bluetooth commands to perform actions. The functionality expose...
CVE-2026-22098CRITICAL9.2Various sensitive information such as passwords and charging card UIDs are written to log files.
CVE-2026-22097CRITICAL9.3The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the...
CVE-2026-22096CRITICAL9.3The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such a...
CVE-2026-22095CRITICAL9.3The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.
CVE-2026-22093CRITICAL9.5The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided b...
CVE-2026-15557HIGH7.3A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInterna...
CVE-2026-15548HIGH8.8A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affects the function sub...
CVE-2026-14846MEDIUM4.5In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation of elements, caused by i...
CVE-2026-13014CRITICAL9.2A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute...
CVE-2026-9708MEDIUM4.9Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming w...
CVE-2026-9597MEDIUM5.4Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before crea...
CVE-2026-9571MEDIUM6.5Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon...
CVE-2026-6850MEDIUM6.5Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of m...
CVE-2026-62143HIGH8.3A Server-Side Request Forgery (SSRF) protection bypass existed in the html_to_markdown expansion module of misp-modules....
CVE-2026-15574HIGH7.5A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorizat...
CVE-2026-15547MEDIUM6.3A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CI...
CVE-2026-15546MEDIUM6.3A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the function sub_2D568 o...
CVE-2026-15545HIGH8.8A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now