2026 CVE Vulnerabilities

61,244 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-50875HIGH8.1Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers...
CVE-2026-50874HIGH8.1An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allo...
CVE-2026-50873CRITICAL9.8An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to exec...
CVE-2026-50872CRITICAL9.8An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitra...
CVE-2026-50871CRITICAL9.8An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscenc...
CVE-2026-50870HIGH7.5An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attacker...
CVE-2026-50869CRITICAL9.8An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplyi...
CVE-2026-49954HIGH8.6Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated a...
CVE-2026-49953MEDIUM6.9Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remo...
CVE-2026-49952CRITICAL9.3Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthentica...
CVE-2026-48114CRITICAL9.8Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and ab...
CVE-2026-47835HIGH7.5In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearc...
CVE-2026-45390CRITICAL9.1In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working dire...
CVE-2026-45389HIGH7.4In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client ...
CVE-2026-45388CRITICAL9.1In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server,...
CVE-2026-41708HIGH7.5In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service ...
CVE-2026-39197MEDIUM6.5An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Serv...
CVE-2026-39196CRITICAL9.8Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in th...
CVE-2026-39118HIGH8.4An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client valid...
CVE-2026-39007HIGH7.5An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via th...
CVE-2026-39006CRITICAL9.8An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component...
CVE-2026-38812CRITICAL9.8RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generatio...
CVE-2026-38329CRITICAL9.8Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoi...
CVE-2026-38065CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ...
CVE-2026-38064CRITICAL9.8Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now