2026 CVE Vulnerabilities

61,772 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-37462HIGH7.5An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a...
CVE-2026-36748CRITICAL9RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.
CVE-2026-36576CRITICAL9.8An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 al...
CVE-2026-36574HIGH7.8A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and e...
CVE-2026-8404MEDIUM5.3An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware...
CVE-2026-7666LOW3.1An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` ...
CVE-2026-6873MEDIUM4.3An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in...
CVE-2026-5241CRITICAL9.6A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-control...
CVE-2026-48587MEDIUM5.3An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Djan...
CVE-2026-47325MEDIUM6.9ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's password...
CVE-2026-47324MEDIUM5.1ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes o...
CVE-2026-44546MEDIUM5.3daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket...
CVE-2026-44545HIGH7.5daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Beca...
CVE-2026-37460HIGH7.5Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 all...
CVE-2026-35193LOW3.1An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware...
CVE-2026-10729LOW1.2An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists i...
CVE-2026-35085HIGH8.8A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system acces...
CVE-2026-35084HIGH8.8A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access ...
CVE-2026-35083HIGH8.8A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.
CVE-2026-35082HIGH8.8The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient...
CVE-2026-35081HIGH8.1The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficien...
CVE-2026-35080HIGH8.1The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insuffic...
CVE-2026-35079HIGH8.1The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient...
CVE-2026-35078HIGH8.1The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficien...
CVE-2026-35077HIGH8.1The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insuffi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now