2026 CVE Vulnerabilities

64,729 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33637MEDIUM6.5Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 ...
CVE-2026-32738MEDIUM6.5libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequen...
CVE-2026-8605CRITICAL9.8In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA syst...
CVE-2026-8604HIGH8.8In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a vic...
CVE-2026-8603CRITICAL9.8In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on t...
CVE-2026-8602CRITICAL9.1In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated at...
CVE-2026-6009HIGH8.7Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allow...
CVE-2026-47107HIGH8.6Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files ...
CVE-2026-33633HIGH8.8Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_dat...
CVE-2026-32134MEDIUM5.9NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles...
CVE-2026-5511LOW2.7In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user i...
CVE-2026-47358HIGH8.6Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded...
CVE-2026-47357HIGH8.6Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the rem...
CVE-2026-47356HIGH8.6Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the fi...
CVE-2026-36829CRITICAL9.8An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7....
CVE-2026-36828HIGH8.8A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and includin...
CVE-2026-36827MEDIUM5.4A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface inv...
CVE-2026-8706MEDIUM6.5Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same devi...
CVE-2026-5804HIGH8.4An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). T...
CVE-2026-37281CRITICAL9.8An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remo...
CVE-2026-31072CRITICAL9.8The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remot...
CVE-2026-31071CRITICAL9.1API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated...
CVE-2026-31070CRITICAL9.8The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileg...
CVE-2026-31069HIGH8.8BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlle...
CVE-2026-30118CRITICAL9.8scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now