2026 CVE Vulnerabilities

57,013 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-61875HIGH8.8luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject Jav...
CVE-2026-61874LOW3.1filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, all...
CVE-2026-59260HIGH8.8OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users t...
CVE-2026-56336MEDIUM6.9Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain ...
CVE-2026-56313HIGH8.1Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that al...
CVE-2026-56308HIGH8.4Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification ...
CVE-2026-56281MEDIUM5.1Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit p...
CVE-2026-56271CRITICAL9.8Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refr...
CVE-2026-56260CRITICAL9.1Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf end...
CVE-2026-56259HIGH8.8Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to ...
CVE-2026-56252MEDIUM5.4Capgo before 12.128.2 contains a scope isolation vulnerability in the POST /webhooks/test endpoint that allows app-scope...
CVE-2026-56241HIGH8.3Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to del...
CVE-2026-56238HIGH8.7Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint t...
CVE-2026-15500MEDIUM6.3A weakness has been identified in AstrBotDevs AstrBot up to 4.25.2. Affected by this vulnerability is the function get_o...
CVE-2026-15499MEDIUM6.3A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25.2. Affected is the function FutureTaskTool.call of...
CVE-2026-15498HIGH7.3A vulnerability was identified in sergomanov SmartHomeAdatum up to cf495353d81b680675eb8d9aa14a318aa45ce12c. This impact...
CVE-2026-15497HIGH7.3A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown function of the file so...
CVE-2026-15496MEDIUM6.3A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2. The impacted element is the function evalIsFailed of...
CVE-2026-15495MEDIUM6.3A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2. The affected element is an unknown function of ...
CVE-2026-15494MEDIUM4.7A flaw has been found in AMTT Hotel Broadband Operation System 1.0. Impacted is an unknown function of the file manager/...
CVE-2026-15493MEDIUM5.1A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. Thi...
CVE-2026-15492MEDIUM4.3A security vulnerability has been detected in igweze wizgrade up to b1d55f22b90cd7e7a6e5002f006d7c649e8086d6. This vulne...
CVE-2026-15491HIGH7.3A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects ...
CVE-2026-15490HIGH7.3A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected...
CVE-2026-15489HIGH7.3A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now