2026 CVE Vulnerabilities

44,021 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-37171MEDIUM5.9A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one ...
CVE-2026-19206MEDIUM5.3A security flaw has been discovered in MZ Automation libiec61850 up to 1.6.1. This affects the function SVReceiver_stopT...
CVE-2026-16637MEDIUM6.5OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlis...
CVE-2026-15570HIGH7.1An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE245...
CVE-2026-66838MEDIUM5.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgr...
CVE-2026-66494HIGH8.7Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unaut...
CVE-2026-56794MEDIUM6.5Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A lo...
CVE-2026-56793CRITICAL9.8Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An ...
CVE-2026-48094MEDIUM5.3The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the abse...
CVE-2026-15816HIGH7.5A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs...
CVE-2026-71560CRITICAL9.1Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0...
CVE-2026-71559HIGH7.5Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a de...
CVE-2026-71558CRITICAL9.8Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from ...
CVE-2026-54218HIGH8.8Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally...
CVE-2026-54217MEDIUM5.3Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send ...
CVE-2026-54216MEDIUM5.3Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By ...
CVE-2026-54215MEDIUM5.3Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An atta...
CVE-2026-54214MEDIUM5.3Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL par...
CVE-2026-54213CRITICAL9.2Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down whe...
CVE-2026-54212CRITICAL9.5Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow...
CVE-2026-54211CRITICAL9.5Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer o...
CVE-2026-54210CRITICAL9.5Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable...
CVE-2026-54209HIGH8.9Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including t...
CVE-2026-54208HIGH8.5Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated...
CVE-2026-54207MEDIUM6.3Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, whi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now