2026 CVE Vulnerabilities

60,340 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56007MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Prod...
CVE-2026-54419CRITICAL9.8claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1...
CVE-2026-54224HIGH7.1UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile o...
CVE-2026-54223HIGH8.6UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any f...
CVE-2026-54222HIGH8.6UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to inte...
CVE-2026-54221MEDIUM5.1UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling ...
CVE-2026-54220HIGH8.6uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an ...
CVE-2026-54219MEDIUM5.1UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly saniti...
CVE-2026-50141HIGH7.1Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's ...
CVE-2026-44942MEDIUM6.5A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series...
CVE-2026-42490MEDIUM6.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-42489MEDIUM5.3[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-42488HIGH8.1Some shadow paging errors paths will switch the page-tables without updating the currently running vCPU reference. This...
CVE-2026-42487HIGH7.9HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the de...
CVE-2026-40457LOW2.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the ...
CVE-2026-40456HIGH8.6An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address p...
CVE-2026-40455HIGH8.6An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within the "tarifflist.php" m...
CVE-2026-12539MEDIUM5.7Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-appl...
CVE-2026-12527MEDIUM6A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V3...
CVE-2026-12039MEDIUM5.7Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network...
CVE-2026-11958HIGH7.3Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and pr...
CVE-2026-11719HIGH8.1An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement...
CVE-2026-11718CRITICAL9.1An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl...
CVE-2026-11717CRITICAL9.1An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl...
CVE-2026-8811HIGH7.1SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An atta...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now