2026 CVE Vulnerabilities

64,779 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-43889MEDIUM6.5Outline is a service that allows for collaborative documentation. Prior to 1.7.0, the shares.create API accepts both col...
CVE-2026-43888HIGH8.7Outline is a service that allows for collaborative documentation. Prior to 1.7.0, ZipHelper.extract computes the extract...
CVE-2026-43887HIGH7.3Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, the Outline comment section perm...
CVE-2026-43886HIGH8.2Outline is a service that allows for collaborative documentation. From 0.84.0 to 1.6.1, a logic error in OAuthInterface....
CVE-2026-43885HIGH7.7WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read API...
CVE-2026-43884HIGH7.7WWBN AVideo is an open source video platform. In versions up to and including 29.0, two endpoints (plugin/AI/receiveAsyn...
CVE-2026-43883MEDIUM4.2WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/PayPalYPT/agreementCancel.jso...
CVE-2026-43882MEDIUM4.3WWBN AVideo is an open source video platform. In versions up to and including 29.0, the unauthenticated plugin/Scheduler...
CVE-2026-43881MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/users.json.php exposes two u...
CVE-2026-43880MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/sendEmail.json.php exposes t...
CVE-2026-43879MEDIUM5.4WWBN AVideo is an open source video platform. In versions up to and including 29.0, an authenticated user can configure ...
CVE-2026-43878MEDIUM6.1WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/Meet/iframe.php echoes the at...
CVE-2026-43877MEDIUM5.4WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/userSavePhoto.php is a legac...
CVE-2026-43876MEDIUM6.4WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/notifySubscribers.json.php t...
CVE-2026-43875MEDIUM6.8WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/MobileManager/oauth2.php comp...
CVE-2026-43873HIGH7.5WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/CloneSite/cloneClient.json.ph...
CVE-2026-42600MEDIUM4.9MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-...
CVE-2026-42564HIGH8.2jotty·page is a self-hosted app for your checklists and notes. Prior to 1.22.0, an unauthenticated path traversal vulner...
CVE-2026-42188MEDIUM4.3Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Prior to 2.9.3, a server-side request...
CVE-2026-42046HIGH7.8libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas...
CVE-2026-34961HIGH7.7barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing val...
CVE-2026-34960HIGH7.1barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_m...
CVE-2026-43874HIGH7.2WWBN AVideo is an open source video platform. In versions up to and including 29.0, the server-side mitigation for the Y...
CVE-2026-43668HIGH7.5A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7....
CVE-2026-43666MEDIUM6.2An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 1...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now