2026 CVE Vulnerabilities

44,049 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-18497HIGH7.1A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for p...
CVE-2026-66914CRITICAL9.2Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated...
CVE-2026-61477LOW2.3An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline ...
CVE-2026-37171MEDIUM5.9A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one ...
CVE-2026-19206MEDIUM5.3A security flaw has been discovered in MZ Automation libiec61850 up to 1.6.1. This affects the function SVReceiver_stopT...
CVE-2026-16637MEDIUM6.5OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlis...
CVE-2026-15570HIGH7.1An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE245...
CVE-2026-66838MEDIUM5.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgr...
CVE-2026-66494HIGH8.7Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unaut...
CVE-2026-56794MEDIUM6.5Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A lo...
CVE-2026-56793CRITICAL9.8Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An ...
CVE-2026-48094MEDIUM5.3The ShareOpenly WordPress plugin prior to version 1.2.1 contains a Cross-Site Scripting vulnerability caused by the abse...
CVE-2026-15816HIGH7.5A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs...
CVE-2026-71560CRITICAL9.1Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0...
CVE-2026-71559HIGH7.5Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a de...
CVE-2026-71558CRITICAL9.8Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from ...
CVE-2026-54218HIGH8.8Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally...
CVE-2026-54217MEDIUM5.3Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send ...
CVE-2026-54216MEDIUM5.3Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By ...
CVE-2026-54215MEDIUM5.3Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An atta...
CVE-2026-54214MEDIUM5.3Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL par...
CVE-2026-54213CRITICAL9.2Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down whe...
CVE-2026-54212CRITICAL9.5Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow...
CVE-2026-54211CRITICAL9.5Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer o...
CVE-2026-54210CRITICAL9.5Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now