2026 CVE Vulnerabilities

64,909 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40552MEDIUM4.7mpGabinet is vulnerable to Remote Command Execution. An authorized user with access to the application and direct access...
CVE-2026-40551HIGH8.4mpGabinet performs client-side authentication. An attacker with access to any application instance connected to the back...
CVE-2026-40550MEDIUM6.9mpGabinet is vulnerable to Privilege Escalation due to excessive database privileges assigned to the user used by the ap...
CVE-2026-7309MEDIUM4.3A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitra...
CVE-2026-7271MEDIUM5.5A vulnerability was detected in DV0x creative-ad-agent up to 751b9e5146604dc65049bd0f62dcbdad6212f8a3. Impacted is an un...
CVE-2026-7269LOW2.4A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected is an unknown function of ...
CVE-2026-5781HIGH8.8An authorization vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/moUser/update' endpoint, could a...
CVE-2026-5780HIGH8.1An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the endpoint '/miner...
CVE-2026-5779HIGH8.8An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/u...
CVE-2026-5435HIGH7.3The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforc...
CVE-2026-7268MEDIUM6.3A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This impacts the function save_category o...
CVE-2026-7267MEDIUM6.3A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects an unknown function of the file /view...
CVE-2026-7266MEDIUM6.3A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. The impacted element is the function save_o...
CVE-2026-7265MEDIUM6.3A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the f...
CVE-2026-3323HIGH7.5An unsecured configuration interface on affected devices allows unauthenticated remote attackers to access sensitive inf...
CVE-2026-7280HIGH8.4AVACAST developed by eMPIA Technology has a Unquoted Service Path vulnerability, allowing privileged local attackers to ...
CVE-2026-7279HIGH8.5AVACAST developed by eMPIA Technology, has a DLL Hijacking vulnerability, allowing authenticated local attackers to plac...
CVE-2026-7264MEDIUM6.3A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function get_cart_items o...
CVE-2026-41636HIGH7.5Uncontrolled Recursion vulnerability in Apache Thrift Node.js bindings This issue affects Apache Thrift: before 0.23.0....
CVE-2026-41607MEDIUM6.5Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommen...
CVE-2026-41606MEDIUM5.3Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are reco...
CVE-2026-41605HIGH7.3Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users ...
CVE-2026-41604HIGH8.2Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommen...
CVE-2026-41603——Rejected reason: This CVE ID is Rejected and will not be used. The record incorrectly described the affected language bi...
CVE-2026-41602HIGH7.5Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation This issue af...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now