2026 CVE Vulnerabilities

64,858 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7742MEDIUM6.3A flaw has been found in CodeAstro Online Classroom 1.0. The affected element is an unknown function of the file /Online...
CVE-2026-7741MEDIUM6.3A vulnerability was detected in CodeAstro Online Classroom 1.0. Impacted is an unknown function of the file /OnlineClass...
CVE-2026-7740LOW3.3A security vulnerability has been detected in justdan96 tsMuxer up to 2.7.0. This issue affects the function VvcVpsUnit:...
CVE-2026-7739LOW3.3A weakness has been identified in justdan96 tsMuxer up to 2.7.0. This vulnerability affects the function HevcVpsUnit::se...
CVE-2026-7738MEDIUM6.3A security flaw has been discovered in puchunjie doc-tools-mcp 1.0.18. This affects the function create_document/open_do...
CVE-2026-7737HIGH7.5A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.P...
CVE-2026-7736HIGH7.5A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry o...
CVE-2026-5335MEDIUM5.3The Magic Export & Import WordPress plugin before 1.2.0 stores exported CSV files at a publicly accessible location, mak...
CVE-2026-43864LOW2.5mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.
CVE-2026-43863LOW3.7mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
CVE-2026-43862LOW3.7In mutt before 2.3.2, the imap_auth_gss security level is mishandled.
CVE-2026-43861LOW3.7mutt before 2.3.2 does not check for '\0' in url_pct_decode.
CVE-2026-43860LOW3.7mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.
CVE-2026-43859LOW3.7mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
CVE-2026-29200CRITICAL9.9A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2...
CVE-2026-29199HIGH8.1phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_ser...
CVE-2026-20451MEDIUM6.7In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege...
CVE-2026-20450MEDIUM6.5In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,...
CVE-2026-20449MEDIUM6.5In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, i...
CVE-2026-20448MEDIUM6.7In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local es...
CVE-2026-20447MEDIUM6.7In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escala...
CVE-2026-7735HIGH7.3A vulnerability was found in osrg GoBGP up to 4.3.0. Affected is the function PathAttributeAigp.DecodeFromBytes of the f...
CVE-2026-7734HIGH7.5A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromByt...
CVE-2026-7733HIGH7.3A flaw has been found in funadmin up to 7.1.0-rc6. This affects the function UploadService::chunkUpload of the file app/...
CVE-2026-7732MEDIUM6.3A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now