2026 CVE Vulnerabilities

61,069 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8461HIGH8.8An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial...
CVE-2026-8024CRITICAL9.8A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoor...
CVE-2026-56012HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi...
CVE-2026-56009MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bri...
CVE-2026-56007MEDIUM5.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Prod...
CVE-2026-54419CRITICAL9.8claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1...
CVE-2026-54224HIGH7.1UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile o...
CVE-2026-54223HIGH8.6UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any f...
CVE-2026-54222HIGH8.6UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to inte...
CVE-2026-54221MEDIUM5.1UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling ...
CVE-2026-54220HIGH8.6uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an ...
CVE-2026-54219MEDIUM5.1UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly saniti...
CVE-2026-50141HIGH7.1Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's ...
CVE-2026-44942MEDIUM6.5A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series...
CVE-2026-42490MEDIUM6.5[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-42489MEDIUM5.3[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2026-42488HIGH8.1Some shadow paging errors paths will switch the page-tables without updating the currently running vCPU reference. This...
CVE-2026-42487HIGH7.9HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the de...
CVE-2026-40457LOW2.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the ...
CVE-2026-40456HIGH8.6An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address p...
CVE-2026-40455HIGH8.6An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within the "tarifflist.php" m...
CVE-2026-12539MEDIUM5.7Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-appl...
CVE-2026-12527MEDIUM6A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V3...
CVE-2026-12039MEDIUM5.7Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network...
CVE-2026-11958HIGH7.3Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and pr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now