2026 CVE Vulnerabilities

64,751 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45494MEDIUM6.1Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-45492MEDIUM5.4Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security featur...
CVE-2026-45230CRITICAL9.1DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelet...
CVE-2026-42822CRITICAL10Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges ove...
CVE-2026-32849MEDIUM5.7NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/op...
CVE-2026-32848MEDIUM5.7NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem...
CVE-2026-29965MEDIUM6.1HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to ...
CVE-2026-29964MEDIUM6.1HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to impro...
CVE-2026-29963HIGH7.5HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /t...
CVE-2026-29962HIGH7.5HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-suppli...
CVE-2026-8843MEDIUM6.5Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to ins...
CVE-2026-45829CRITICAL10A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an un...
CVE-2026-41085HIGH8.8Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an auth...
CVE-2026-38719MEDIUM6.2OpENer v2.3-558-g1e99582 contains an out-of-bounds read vulnerability in the Common Packet Format (CPF) parser, specific...
CVE-2026-36438MEDIUM5.3An issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive information ...
CVE-2026-20685MEDIUM6.5An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addres...
CVE-2026-41949HIGH7.5Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any a...
CVE-2026-41948CRITICAL9.4Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate reque...
CVE-2026-41947CRITICAL9.3Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set ...
CVE-2026-39079HIGH7.5An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive info...
CVE-2026-26462HIGH7.3Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration...
CVE-2026-42009HIGH7.5A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) pac...
CVE-2026-8803MEDIUM6.3A flaw has been found in opensourcepos Open Source Point of Sale up to 3.4.2. Impacted is the function Login of the file...
CVE-2026-7304CRITICAL9.8SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-lo...
CVE-2026-7302CRITICAL9.1SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an atta...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now