2026 CVE Vulnerabilities

59,898 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-57950HIGH8.6ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderCon...
CVE-2026-57949HIGH7.1ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module...
CVE-2026-57948HIGH7.6Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the...
CVE-2026-57947HIGH8.5Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that al...
CVE-2026-57946MEDIUM6.3Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attacke...
CVE-2026-57945MEDIUM5.3PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin us...
CVE-2026-57943MEDIUM6LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that...
CVE-2026-57942MEDIUM6.9LibreTranslate through 1.9.7, fixed in commit 397fd22, contains an IP spoofing vulnerability in the get_remote_address()...
CVE-2026-56783HIGH7.1Parseable before 2.9.2 contains an information disclosure vulnerability in the notification-target API endpoints that re...
CVE-2026-56782CRITICAL9.8Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that all...
CVE-2026-56781MEDIUM6.9Teable before 2026-06-15T04-43-24Z.1912 contains an improper access control vulnerability that allows anonymous attacker...
CVE-2026-56780HIGH7.7Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/passwor...
CVE-2026-56285HIGH8.6Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded defaul...
CVE-2026-36848HIGH7.5Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.
CVE-2026-13592HIGH7.3A vulnerability was detected in liftoff-sr CIPster up to e8e9dba09bf56962807d3504b783ccdb6287f3e4. Affected by this issu...
CVE-2026-11720CRITICAL9.1A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstr...
CVE-2026-13752HIGH8Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attac...
CVE-2026-13751CRITICAL9.6Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request for...
CVE-2026-13591MEDIUM5A weakness has been identified in DeepMyst Mysti 0.4.0. Affected is the function _isTrackedConversation of the file src/...
CVE-2026-13590MEDIUM5.6A security flaw has been discovered in seladb PcapPlusPlus 25.05. This impacts the function pcpp::ModbusLayer::getLength...
CVE-2026-13589MEDIUM5.6A vulnerability was identified in seladb PcapPlusPlus 25.05. This affects the function pcpp::TelnetLayer::getSubCommand ...
CVE-2026-13588MEDIUM5.6A vulnerability was determined in seladb PcapPlusPlus 25.05. The impacted element is the function pcpp::SSLClientHelloMe...
CVE-2026-12912HIGH7.3A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLo...
CVE-2026-12672Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-9105MEDIUM6.5An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now