2026 CVE Vulnerabilities

64,889 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-7392MEDIUM6.3A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This impacts the function dele...
CVE-2026-7391MEDIUM6.3A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function save_supplier...
CVE-2026-6915MEDIUM4.3An authorization flaw in the user management command could allow an authenticated user to make limited changes to authen...
CVE-2026-6914HIGH7.5Computing the MD5 checksum of a malformed BSON object under specific conditions may cause loss of availability in MongoD...
CVE-2026-0206MEDIUM4.9A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewal...
CVE-2026-0205MEDIUM6.8A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted ser...
CVE-2026-0204HIGH8A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be access...
CVE-2026-7390LOW3.5A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. The impacted element is the func...
CVE-2026-7389HIGH7.3A security vulnerability has been detected in EyouCMS up to 1.7.9. The affected element is the function GetSortData of t...
CVE-2026-7388MEDIUM4.7A weakness has been identified in EyouCMS up to 1.7.9. Impacted is the function editFile of the file application/admin/l...
CVE-2026-7386HIGH7.3A flaw has been found in fatbobman mail-mcp-bridge up to 1.3.3. Affected is an unknown function of the file src/mail_mcp...
CVE-2026-6849HIGH8.8Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILG...
CVE-2026-5166CRITICAL9.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software ...
CVE-2026-42198HIGH7.5pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to ...
CVE-2026-41940CRITICAL9.8cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthe...
CVE-2026-40230MEDIUM5.4Helpy contains a stored cross-site scripting vulnerability in the knowledge base Doc rendering logic. An authenticated a...
CVE-2026-40229MEDIUM5.4Helpy contains a stored cross-site scripting vulnerability in the post author display logic. Any registered user can per...
CVE-2026-38993MEDIUM6.5Cockpit 2.13.5 and earlier is vulnerable to directory traversal via the Buckets component. This vulnerability allows aut...
CVE-2026-38991HIGH8.8Cockpit 2.13.5 and earlier is affected by a misconfiguration within the Bucket component _isFileTypeAllowed function whe...
CVE-2026-37555HIGH7.5An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) c...
CVE-2026-30769HIGH7.8An issue in the TVicPort64.sys component of EnTech Taiwan TVicPort Product v4.0, File v5.2.1.0 allows attackers to escal...
CVE-2026-2810MEDIUM6.8Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The succe...
CVE-2026-7384HIGH7.3A vulnerability was detected in ezequiroga mcp-bases 357ca19c7a49a9b9cb2ef639b366f03aba8bea39/c630b8ab0f970614d42da8e566...
CVE-2026-7111HIGH8.4Text::CSV_XS versions before 1.62 for Perl have a use-after-free when registered callbacks extend the Perl argument stac...
CVE-2026-5161HIGH8.8Improper link resolution before file access ('link following') vulnerability in TUBITAK BILGEM Software Technologies Res...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now