2026 CVE Vulnerabilities

44,049 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54209HIGH8.9Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including t...
CVE-2026-54208HIGH8.5Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated...
CVE-2026-54207MEDIUM6.3Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, whi...
CVE-2026-54206MEDIUM6.3Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, wh...
CVE-2026-54205MEDIUM6.3Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname”...
CVE-2026-54204HIGH7.7Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set t...
CVE-2026-54203CRITICAL9.2Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensiti...
CVE-2026-54202HIGH8.5Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation funct...
CVE-2026-54201MEDIUM6.9Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks when serving these lo...
CVE-2026-54200HIGH8.4Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax,...
CVE-2026-54199MEDIUM5.3Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the applic...
CVE-2026-12071MEDIUM5.3The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which is appended ...
CVE-2026-12070HIGH8.4Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, ...
CVE-2026-9169HIGH8.8DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitr...
CVE-2026-66493MEDIUM6.4Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths...
CVE-2026-66492MEDIUM6.1Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths...
CVE-2026-66491HIGH8.2Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the g...
CVE-2026-49008MEDIUM6.5By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to the integrity...
CVE-2026-18938MEDIUM6.2A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit a...
CVE-2026-49007HIGH7.5By accessing unencrypted information in the device firmware, an attacker can obtain the initial login credentials for th...
CVE-2026-49006MEDIUM5.3By accessing unencrypted information in the device firmware, an attacker can obtain credentials related to TLS transmiss...
CVE-2026-19079MEDIUM4.4A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. W...
CVE-2026-16027MEDIUM5.4Server-Side request forgery (SSRF) vulnerability in Revenue Administration Türkiye's E-Signature allows Server Side Requ...
CVE-2026-15239MEDIUM5.3The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin before 1.42.0 does not bind its Turnstile validation cache...
CVE-2026-15211MEDIUM5.9The Subscriptions for WooCommerce WordPress plugin before 2.0.1 does not validate the payment amount or bind the PayPal ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now