2026 CVE Vulnerabilities

62,186 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-46376CRITICAL9.8FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access...
CVE-2026-46337MEDIUM5.3WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary...
CVE-2026-45731MEDIUM4.9WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relat...
CVE-2026-45707HIGH8.1n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-45620MEDIUM5.3WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or...
CVE-2026-45619MEDIUM6.5WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and o...
CVE-2026-45615HIGH8.2mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decod...
CVE-2026-45610MEDIUM6.5WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability o...
CVE-2026-45582MEDIUM6.5n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-45580MEDIUM5.4WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability....
CVE-2026-45578HIGH8.8WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The...
CVE-2026-45555HIGH7.8Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0....
CVE-2026-44698HIGH8.3Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for ...
CVE-2026-44239HIGH8.8FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes P...
CVE-2026-44238HIGH8.8FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through...
CVE-2026-44237HIGH8.1FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently ...
CVE-2026-40528HIGH7.8OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_valu...
CVE-2026-40510MEDIUM6.8OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history...
CVE-2026-10075MEDIUM6.9DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read ...
CVE-2026-10074MEDIUM6.9DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to explo...
CVE-2026-10073HIGH8.7DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to ...
CVE-2026-10072HIGH8.6DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to up...
CVE-2026-10061CRITICAL9.8A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. ...
CVE-2026-10060CRITICAL9.8A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /gofor...
CVE-2026-9509HIGH8.7An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now