2026 CVE Vulnerabilities

60,149 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-55477HIGH7.23X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse th...
CVE-2026-54036HIGH8.1LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the GET /api/auth/2fa/en...
CVE-2026-4522MEDIUM6.7Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Intercepti...
CVE-2026-48946MEDIUM6.3The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php ma...
CVE-2026-48945MEDIUM5.3The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only re...
CVE-2026-48944MEDIUM6.5The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SI...
CVE-2026-48943MEDIUM6.5K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by inc...
CVE-2026-48942MEDIUM6.1K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both...
CVE-2026-48941MEDIUM6.5The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to ad...
CVE-2026-48940LOW3.4A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field ...
CVE-2026-12844HIGH7.5List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function. pairwise() coll...
CVE-2026-6432MEDIUM5.3Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.
CVE-2026-57588LOW3.3A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by ...
CVE-2026-57587MEDIUM5.3A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a...
CVE-2026-57536MEDIUM6.3Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a success...
CVE-2026-57535LOW2.1Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src ...
CVE-2026-57534LOW2.1Malicious HTML content could be injected into the content of a page in the pretix-pages plugin.
CVE-2026-57533LOW2.1Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since...
CVE-2026-57532HIGH8.8Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF ...
CVE-2026-57437MEDIUM5.3Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::XPath...
CVE-2026-57436MEDIUM5.3Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::Docum...
CVE-2026-57435HIGH7.5Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby nat...
CVE-2026-57434HIGH7.5Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a ...
CVE-2026-57236HIGH8.2Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, calling Document#enc...
CVE-2026-57235HIGH8.2Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::NodeS...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now