2026 CVE Vulnerabilities

60,149 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-11625HIGH7.5Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is in...
CVE-2026-57881CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.1...
CVE-2026-57880CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12...
CVE-2026-57879CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12...
CVE-2026-57878CRITICAL9.8An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1....
CVE-2026-57877HIGH8.6An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier....
CVE-2026-57876HIGH7.5An unauthenticated out-of-bounds write vulnerability exists in onvif.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 an...
CVE-2026-57875HIGH7.5An unauthenticated NULL pointer dereference vulnerability exists in the HTTP request parsing logic of multiple CGI compo...
CVE-2026-57874HIGH7.5An unauthenticated buffer overflow vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V...
CVE-2026-57873HIGH7.5An unauthenticated NULL pointer dereference vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-...
CVE-2026-57872HIGH7.5An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.1...
CVE-2026-49486HIGH7.5The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p(...
CVE-2026-2053CRITICAL10The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or ...
CVE-2026-8380MEDIUM6.5The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post...
CVE-2026-10835HIGH7.7The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one ...
CVE-2026-10823HIGH7.5The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and do...
CVE-2026-8797HIGH8.5An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access t...
CVE-2026-8661MEDIUM4.8Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions ...
CVE-2026-50745MEDIUM6.1A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script w...
CVE-2026-50744MEDIUM4.3A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login me...
CVE-2026-50742MEDIUM5.4A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revi...
CVE-2026-50741HIGH8.8Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix ...
CVE-2026-50740MEDIUM5.4A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and ea...
CVE-2026-50739MEDIUM4.3A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation o...
CVE-2026-48936LOW3.3A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now