2026 CVE Vulnerabilities

61,773 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-0018MEDIUM5.5In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to impro...
CVE-2026-0016LOW3.3In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings acro...
CVE-2026-0009HIGH7.8In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalat...
CVE-2026-5419LOW3.7A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing si...
CVE-2026-49433MEDIUM5The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an ...
CVE-2026-49140MEDIUM5.3Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler t...
CVE-2026-49139HIGH7Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handl...
CVE-2026-49138MEDIUM5.3Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows re...
CVE-2026-49136HIGH8.7Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() ...
CVE-2026-49135HIGH7.2CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to acces...
CVE-2026-49134HIGH7.5CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers ...
CVE-2026-37234HIGH8.2FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs. On disc...
CVE-2026-24751HIGH8.2Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Dat...
CVE-2026-10289MEDIUM4.3A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown fu...
CVE-2026-10288HIGH7.3A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the functio...
CVE-2026-10287HIGH7.3A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get...
CVE-2026-10286MEDIUM6.3A vulnerability was found in CodeAstro Payroll System 1.0. This affects an unknown part of the file /home_employee.php. ...
CVE-2026-10285MEDIUM5.4A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the functi...
CVE-2026-10284MEDIUM5.4A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the functio...
CVE-2026-9614HIGH8.8An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticate...
CVE-2026-9330HIGH8.5IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deseria...
CVE-2026-9319CRITICAL9IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of...
CVE-2026-9311CRITICAL9IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security co...
CVE-2026-8644CRITICAL9.1IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
CVE-2026-7770HIGH8.8IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now