2026 CVE Vulnerabilities

64,617 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40034HIGH8.5gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmo...
CVE-2026-40033HIGH8.8FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers t...
CVE-2026-9544HIGH7.3A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by thi...
CVE-2026-9543CRITICAL9.8A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the fi...
CVE-2026-9542MEDIUM6.3A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of ...
CVE-2026-9541MEDIUM5.3A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqob...
CVE-2026-9540MEDIUM5.5A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component ...
CVE-2026-8479MEDIUM6.9IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially craf...
CVE-2026-8174MEDIUM5.7Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wo...
CVE-2026-7374CRITICAL9.9A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with ed...
CVE-2026-7310MEDIUM4.4A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious ...
CVE-2026-48136MEDIUM4.1When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access...
CVE-2026-48135MEDIUM5.3A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request pa...
CVE-2026-48134MEDIUM5.6When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific...
CVE-2026-48133HIGH7.5When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to r...
CVE-2026-48132HIGH8.1The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As...
CVE-2026-48131HIGH8.1The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage o...
CVE-2026-44410LOW3.8This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended...
CVE-2026-39661HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-39642MEDIUM5.3Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code...
CVE-2026-27427MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mas...
CVE-2026-25713HIGH7.8A heap-based buffer overflow vulnerability exists in the ID3v2 parsing functionality of MediaInfoLib (version(s): 26.01)...
CVE-2026-25104HIGH7.8A heap-based buffer overflow vulnerability exists in the LXF parsing functionality of MediaInfoLib (version(s): 26.01). ...
CVE-2026-24638MEDIUM4.3Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Cont...
CVE-2026-24590MEDIUM5.3Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Config...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now