2026 CVE Vulnerabilities

59,915 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56124HIGH8.7phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers t...
CVE-2026-55844HIGH7.5Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The...
CVE-2026-55607HIGH8.8Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of w...
CVE-2026-49049HIGH7.5The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary fil...
CVE-2026-46406MEDIUM6.1Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a ha...
CVE-2026-13579MEDIUM6.3A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown fu...
CVE-2026-13578MEDIUM6.3A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an...
CVE-2026-13574LOW3.3A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr i...
CVE-2026-13573LOW3.3A vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the li...
CVE-2026-13572MEDIUM6.3A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown functi...
CVE-2026-13571MEDIUM5.5A flaw has been found in SourceCodester Simple Food Ordering System 1.0. The affected element is an unknown function of ...
CVE-2026-56457MEDIUM4.3HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This...
CVE-2026-54371HIGH7.1attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows ...
CVE-2026-54370HIGH7.2acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local...
CVE-2026-54369HIGH7.1acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(...
CVE-2026-40524HIGH8.1FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the fil...
CVE-2026-40523HIGH8.1FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Audit Trail report handler that allows authe...
CVE-2026-40522HIGH7.1FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows au...
CVE-2026-40521HIGH8.8FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authe...
CVE-2026-13676HIGH7.5fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The I...
CVE-2026-13570LOW3.5A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the f...
CVE-2026-13569MEDIUM4.7A security vulnerability has been detected in weng-xianhu EyouCMS up to 1.7.1. This issue affects some unknown processin...
CVE-2026-13568HIGH7.3A weakness has been identified in SourceCodester Inventory Management System 1.0. This vulnerability affects unknown cod...
CVE-2026-13567MEDIUM4.3A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Fr...
CVE-2026-13566HIGH7.3A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now