2026 CVE Vulnerabilities

63,655 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45615HIGH8.2mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decod...
CVE-2026-45610MEDIUM6.5WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability o...
CVE-2026-45582MEDIUM6.5n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-45580MEDIUM5.4WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability....
CVE-2026-45578HIGH8.8WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The...
CVE-2026-45555HIGH7.8Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0....
CVE-2026-44698HIGH8.3Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for ...
CVE-2026-44239HIGH8.8FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes P...
CVE-2026-44238HIGH8.8FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through...
CVE-2026-44237HIGH8.1FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently ...
CVE-2026-40528HIGH7.8OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_valu...
CVE-2026-40510MEDIUM6.8OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history...
CVE-2026-10075MEDIUM6.9DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read ...
CVE-2026-10074MEDIUM6.9DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to explo...
CVE-2026-10073HIGH8.7DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to ...
CVE-2026-10072HIGH8.6DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to up...
CVE-2026-10061CRITICAL9.8A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. ...
CVE-2026-10060CRITICAL9.8A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /gofor...
CVE-2026-9509HIGH8.7An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated...
CVE-2026-9508CRITICAL10Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow bac...
CVE-2026-8326CRITICAL10Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitra...
CVE-2026-49324MEDIUM4.6Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025...
CVE-2026-49323MEDIUM4.3Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcyc...
CVE-2026-48527HIGH8.7HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by...
CVE-2026-45611——Rejected reason: Further research determined the issue is not a vulnerability.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now