2026 CVE Vulnerabilities

64,803 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41654HIGH8.1Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (de...
CVE-2026-41650MEDIUM6.1fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version ...
CVE-2026-41519MEDIUM5.4Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions ...
CVE-2026-41505HIGH8.7RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation ...
CVE-2026-41422HIGH8.3Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column an...
CVE-2026-36458CRITICAL9.8ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated i...
CVE-2026-32686MEDIUM6.9Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The ...
CVE-2026-6795CRITICAL9.6URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive...
CVE-2026-41685MEDIUM4.3Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large amount of data by auth...
CVE-2026-41684MEDIUM6.5Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline back...
CVE-2026-41648MEDIUM5Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs...
CVE-2026-41647MEDIUM6.5Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an ...
CVE-2026-41589CRITICAL9.6Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP...
CVE-2026-41554HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricks Builder all...
CVE-2026-41490HIGH8.3Dagster is an orchestration platform for the development, production, and observation of data assets. Prior to Dagster C...
CVE-2026-30496CRITICAL9.8The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes an HTTP API on TCP port 2345 that...
CVE-2026-30495HIGH8.8The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP...
CVE-2026-8094CRITICAL9.8Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.
CVE-2026-8093HIGH8.1Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume th...
CVE-2026-8092HIGH8.1Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed ...
CVE-2026-8091CRITICAL9.8Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thund...
CVE-2026-8090HIGH7.3Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, ...
CVE-2026-6002HIGH8.8Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Te...
CVE-2026-5791MEDIUM6.5Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site...
CVE-2026-5784HIGH8.8Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now