2026 CVE Vulnerabilities

60,251 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-10687Rejected reason: This CVE Record has been rejected by the Zephyr Project CNA. Subsequent analysis, confirmed with the fi...
CVE-2026-46580HIGH8.8In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were auto...
CVE-2026-44691HIGH8.8In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/t...
CVE-2026-44688HIGH8.8In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its...
CVE-2026-22551MEDIUM6.5In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP r...
CVE-2026-11791MEDIUM5A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees...
CVE-2026-9158CRITICAL9.8In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interfac...
CVE-2026-8461HIGH8.8An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial...
CVE-2026-8024CRITICAL9.8A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoor...
CVE-2026-56012HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi...
CVE-2026-56009MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bri...
CVE-2026-56007MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Prod...
CVE-2026-54419CRITICAL9.8claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1...
CVE-2026-54224HIGH7.1UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile o...
CVE-2026-54223HIGH8.6UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any f...
CVE-2026-54222HIGH8.6UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to inte...
CVE-2026-54221MEDIUM5.1UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling ...
CVE-2026-54220HIGH8.6uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an ...
CVE-2026-54219MEDIUM5.1UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly saniti...
CVE-2026-50141HIGH7.1Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's ...
CVE-2026-44942MEDIUM6.5A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series...
CVE-2026-42490MEDIUM6.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-42489MEDIUM5.3[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-42488HIGH8.1Some shadow paging errors paths will switch the page-tables without updating the currently running vCPU reference. This...
CVE-2026-42487HIGH7.9HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the de...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now