2026 CVE Vulnerabilities

65,293 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-102010HIGH7A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, t...
CVE-2026-101139LOW2.7A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of the file /admin/sales/in...
CVE-2026-101132LOW3.1A security flaw has been discovered in DeepSeek deepseek-harness up to 0.1.7-rc.2. The affected element is the function ...
CVE-2026-101131LOW3.3A vulnerability was identified in deepseek-ai deepseek-harness up to 0.1.5-rc.3. Impacted is an unknown function of the ...
CVE-2026-101111MEDIUM5.3Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail...
CVE-2026-101110CRITICAL9.3Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s ...
CVE-2026-101109MEDIUM5.3Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-...
CVE-2026-101108CRITICAL9.3Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager....
CVE-2026-101105MEDIUM6.3A vulnerability was determined in code-projects Matrimonial System 1.0. The affected element is the function processprof...
CVE-2026-100753MEDIUM5.3Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public pro...
CVE-2026-100752CRITICAL9.3Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatem...
CVE-2026-96740MEDIUM6.5A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console cu...
CVE-2026-75600HIGH8.6FreePBX is an open source IP PBX. Prior to version 17.0.9, authenticated users who are authorized to access the GraphQL ...
CVE-2026-55160HIGH7.6Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery ...
CVE-2026-55157HIGH8.4Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge gra...
CVE-2026-55156MEDIUM5.3Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge gra...
CVE-2026-54710HIGH8.6FreePBX is an open source IP PBX. Prior to versions 16.0.40 and 17.0.7, a critical remote code execution (RCE) vulnerabi...
CVE-2026-54708HIGH8.6FreePBX is an open source IP PBX. Prior to versions 16.0.72 and 17.0.7, a critical vulnerability exists in the FreePBX b...
CVE-2026-54675HIGH8.7FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, a critical vulnerability exists in the sound lan...
CVE-2026-54674HIGH8.6FreePBX is an open source IP PBX. Prior to versions 16.0.39 and 17.0.7, users authenticated via User Control Panel (UCP)...
CVE-2026-49994CRITICAL9.1Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML ...
CVE-2026-45562HIGH7.7FreePBX is an open source IP PBX. Prior to versions 16.0.4 and 17.0.6, the FreePBX Music on Hold (MoH) module contains a...
CVE-2026-101913MEDIUM6.3ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, the Address...
CVE-2026-101912MEDIUM6.3ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSub...
CVE-2026-101911MEDIUM6.3ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now