2026 CVE Vulnerabilities

44,805 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-72583MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in fastschema through v0.15.1 allows a low-privileged authenticated us...
CVE-2026-72582HIGH7.5A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to cras...
CVE-2026-72581HIGH8.6A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker...
CVE-2026-72580CRITICAL9.8An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute a...
CVE-2026-72579HIGH7.5An OS command injection vulnerability in NASA HyperCP (main branch) allows a network-adjacent attacker who can intercept...
CVE-2026-72578HIGH8.8A cross-site request forgery (CSRF) vulnerability in FreePBX Framework 17.0 allows an unauthenticated remote attacker to...
CVE-2026-72577CRITICAL9.8Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary ...
CVE-2026-72576MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Bludit 4.0.0-beta allows a low-privileged authenticated user (Autho...
CVE-2026-72575CRITICAL9.1An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read, crea...
CVE-2026-72574MEDIUM6.1A host header injection vulnerability in picocms/Pico through 2.1.4 allows an unauthenticated remote attacker to control...
CVE-2026-72573HIGH8.8An OS command injection vulnerability in 4xmen/pm2panel (all versions) allows an authenticated remote attacker to execut...
CVE-2026-72572HIGH7.5A path traversal vulnerability in o1lab/xmysql (all versions) allows an unauthenticated remote attacker to read and down...
CVE-2026-72571HIGH7.5A path traversal vulnerability in mustafaakin/cast-localvideo (all versions) allows an unauthenticated remote attacker t...
CVE-2026-72570MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to injec...
CVE-2026-72569CRITICAL9.1A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to d...
CVE-2026-72568HIGH7.1An out-of-bounds read vulnerability in Redis through 8.8.1 allows an adjacent unauthenticated attacker to cause denial o...
CVE-2026-72567CRITICAL9.8An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated rem...
CVE-2026-72566HIGH7.7A server-side request forgery (SSRF) vulnerability in automatisch through commit 41f3c56 allows a low-privileged authent...
CVE-2026-72565CRITICAL9.8A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-tab...
CVE-2026-72564CRITICAL9.6An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to aut...
CVE-2026-71394MEDIUM5.3GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory() in src/sfnt.c. Due to a...
CVE-2026-71393MEDIUM5.3GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function compute...
CVE-2026-71392MEDIUM5.3GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. Whe...
CVE-2026-71391MEDIUM5.3GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index b...
CVE-2026-66642MEDIUM5.4Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now