2026 CVE Vulnerabilities

61,244 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-53705HIGH7.6A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack f...
CVE-2026-53704HIGH7.1A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file cont...
CVE-2026-53703HIGH7.1A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file,...
CVE-2026-52722HIGH7.1A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor d...
CVE-2026-52721MEDIUM5.3Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trig...
CVE-2026-52720HIGH8.8A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorr...
CVE-2026-52719HIGH7.1An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser rea...
CVE-2026-52718MEDIUM6.5A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse...
CVE-2026-50892MEDIUM6.5Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows auth...
CVE-2026-50891HIGH8.1Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges ...
CVE-2026-50890CRITICAL9.8Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /sto...
CVE-2026-50889HIGH7.5An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (...
CVE-2026-50888HIGH8.1An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillec...
CVE-2026-50887CRITICAL9.1A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attac...
CVE-2026-50886CRITICAL9.1Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan inte...
CVE-2026-50885HIGH7.5Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to...
CVE-2026-50884HIGH8.8Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sens...
CVE-2026-50883CRITICAL9.6An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute ...
CVE-2026-50882HIGH7.5An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS)...
CVE-2026-50881HIGH8.1Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate p...
CVE-2026-50880CRITICAL9.8An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary cod...
CVE-2026-50879HIGH7.5An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Ser...
CVE-2026-50878HIGH7.5An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Serv...
CVE-2026-50877HIGH7.5An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names cont...
CVE-2026-50876MEDIUM5.4A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HT...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now