2026 CVE Vulnerabilities

63,169 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-10042CRITICAL9.8manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deseri...
CVE-2026-49325MEDIUM4.6Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 ...
CVE-2026-49318LOW2.4Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 m...
CVE-2026-49317LOW2.4Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 m...
CVE-2026-49316MEDIUM4.6Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allow...
CVE-2026-47696MEDIUM4.3WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits t...
CVE-2026-47694MEDIUM5.4WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input a...
CVE-2026-46510HIGH8.2form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys ...
CVE-2026-46376CRITICAL9.8FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access...
CVE-2026-46337MEDIUM5.3WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary...
CVE-2026-45731MEDIUM4.9WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relat...
CVE-2026-45707HIGH8.1n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-45620MEDIUM5.3WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or...
CVE-2026-45619MEDIUM6.5WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and o...
CVE-2026-45615HIGH8.2mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decod...
CVE-2026-45610MEDIUM6.5WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability o...
CVE-2026-45582MEDIUM6.5n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-45580MEDIUM5.4WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability....
CVE-2026-45578HIGH8.8WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The...
CVE-2026-45555HIGH7.8Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0....
CVE-2026-44698HIGH8.3Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for ...
CVE-2026-44239HIGH8.8FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes P...
CVE-2026-44238HIGH8.8FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through...
CVE-2026-44237HIGH8.1FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently ...
CVE-2026-40528HIGH7.8OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_valu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now