2026 CVE Vulnerabilities

64,617 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-42337MEDIUM5.3MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broken access control vul...
CVE-2026-42336MEDIUM5.1MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forge...
CVE-2026-42335MEDIUM6.3MaxKB is an open-source AI assistant for enterprise. Prior to 2.8.1, MaxKB v2.8.0 and prior are vulnerable to a server-s...
CVE-2026-36239MEDIUM4.3PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality
CVE-2026-9575HIGH7.3A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown...
CVE-2026-9574HIGH7.3A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code ...
CVE-2026-9573HIGH7.3A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of t...
CVE-2026-8453——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-44833HIGH7.1Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows att...
CVE-2026-44832HIGH8.8Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permissio...
CVE-2026-44831MEDIUM5.4Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by...
CVE-2026-44214MEDIUM5.3eventsource-encoder encodes events as well-formed EventSource/Server Sent Event (SSE) messages. Prior to 1.0.2, eventsou...
CVE-2026-27331MEDIUM6.3Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Contro...
CVE-2026-25444MEDIUM4.3Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Contr...
CVE-2026-25426MEDIUM5.3Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectl...
CVE-2026-24520MEDIUM4.3Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting Incorrectly Configured Access Control Secu...
CVE-2026-9572MEDIUM5.5A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample o...
CVE-2026-9568MEDIUM5A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDo...
CVE-2026-8890HIGH8.8code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impe...
CVE-2026-4051HIGH7.2IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to e...
CVE-2026-48689CRITICAL9.8FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffe...
CVE-2026-3660CRITICAL9.8IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update se...
CVE-2026-3603HIGH7.1IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Int...
CVE-2026-9567LOW3.3A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia...
CVE-2026-9566MEDIUM4.3A vulnerability was identified in teableio teable up to 1.9.x. This impacts an unknown function of the file apps/nextjs-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now