2026 CVE Vulnerabilities

61,327 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49482MEDIUM4.3ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5 contains an imprope...
CVE-2026-10676Rejected reason: This CVE Record has been rejected by the Zephyr Project CNA. Subsequent analysis determined that the ad...
CVE-2026-47238MEDIUM6.5ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can e...
CVE-2026-45418HIGH8.8ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can up...
CVE-2026-45060CRITICAL9.8ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php en...
CVE-2026-42846CRITICAL9.8ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature ...
CVE-2026-6250HIGH8.1An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of use...
CVE-2026-49060CRITICAL9.8Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This iss...
CVE-2026-45174HIGH7.8Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the...
CVE-2026-45173MEDIUM6.5Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validatio...
CVE-2026-45172HIGH8.8Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, ...
CVE-2026-45171HIGH8.8Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) v...
CVE-2026-44890HIGH7.5Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to ...
CVE-2026-44250HIGH7.5Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to ...
CVE-2026-44249HIGH8.1Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to vers...
CVE-2026-42653HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.Mihai SliceWP...
CVE-2026-42647CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport ...
CVE-2026-39494CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Produc...
CVE-2026-12035HIGH8.8Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exp...
CVE-2026-12034HIGH8.3Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 al...
CVE-2026-12033MEDIUM5.3Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromise...
CVE-2026-12032LOW3.1Inappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker ...
CVE-2026-12031HIGH8.3Inappropriate implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who ...
CVE-2026-12030HIGH8.3Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had comprom...
CVE-2026-12029HIGH8.3Use after free in Video in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromise...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now