2026 CVE Vulnerabilities

62,793 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-37222HIGH7.5FlexRIC v2.0.0 uses hardcoded assertions to validate Information Element (IE) counts in decoded E2AP messages. A remote ...
CVE-2026-10275MEDIUM5A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs1...
CVE-2026-10274MEDIUM6.3A vulnerability was determined in indrasishbanerjee aem-mcp-server up to b5f833aef9b5dfd17a5991b3b18a8a11edbdc583. This ...
CVE-2026-10273HIGH7.3A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBui...
CVE-2026-10272MEDIUM6.5A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The imp...
CVE-2026-10271MEDIUM6.3A flaw has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The affected ele...
CVE-2026-10270HIGH7.5A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprintf of the file /http...
CVE-2026-10269MEDIUM6.3A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticat...
CVE-2026-10268LOW3.3A weakness has been identified in janet-lang janet up to 1.41.0. This vulnerability affects the function unmarshal_one_f...
CVE-2026-10118HIGH7.8A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious...
CVE-2026-8931CRITICAL9.4A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.
CVE-2026-48879CRITICAL9.8Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from ...
CVE-2026-48866CRITICAL9.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravit...
CVE-2026-48865HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPre...
CVE-2026-48839HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Stat...
CVE-2026-48559MEDIUM5.4Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers ...
CVE-2026-42683HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBookin...
CVE-2026-42682CRITICAL9.1Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Sec...
CVE-2026-42681HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf al...
CVE-2026-42680CRITICAL9.8Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows P...
CVE-2026-42251HIGH8.7Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the applicat...
CVE-2026-37221HIGH7.5FlexRIC v2.0.0 crashes when receiving a RIC_SUBSCRIPTION_RESPONSE with an unknown ric_id that has no corresponding pendi...
CVE-2026-37220HIGH7.5FlexRIC v2.0.0 crashes when an SCTP association is closed before an E2_SETUP_REQUEST is sent. The near-RT RIC assumes a ...
CVE-2026-10533MEDIUM5A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQ...
CVE-2026-10267LOW3.3A security flaw has been discovered in janet-lang janet up to 1.41.0. This affects the function doframe of the file src/...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now