2026 CVE Vulnerabilities

65,056 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-40301MEDIUM4.7DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.10, DOMSanitizer::sanitize() allows <style...
CVE-2026-40299MEDIUM6.9next-intl provides internationalization for Next.js. Applications using the `next-intl` middleware prior to version 4.9....
CVE-2026-40293MEDIUM6.5OpenFGA is an authorization/permission engine built for developers. In versions 0.1.4 through 1.13.1, when OpenFGA is co...
CVE-2026-40286HIGH7.5WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul...
CVE-2026-40285HIGH8.8WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in da...
CVE-2026-40284MEDIUM6.8WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul...
CVE-2026-40282MEDIUM6.4WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul...
CVE-2026-40196HIGH8.1HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultG...
CVE-2026-40155MEDIUM5.4The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In versions 4.12.0 thro...
CVE-2026-35603HIGH7.3Claude Code is an agentic coding tool. In versions prior to 2.1.75 on Windows, Claude Code loaded the system-wide defaul...
CVE-2026-35512HIGH8.8xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynam...
CVE-2026-35402LOW2.3mcp-neo4j-cypher is an MCP server for executing Cypher queries against Neo4j databases. In versions prior to 0.6.0, the ...
CVE-2026-33689CRITICAL9.1xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentic...
CVE-2026-33436MEDIUM6.1Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. In versions prior to ...
CVE-2026-33145MEDIUM6.3xrdp is an open source RDP server. Versions through 0.10.5 allow an authenticated remote user to execute arbitrary comma...
CVE-2026-23500CRITICAL9.1Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versio...
CVE-2026-40461HIGH7.5Anviz CX2 Lite and CX7 are vulnerable to unauthenticated POST requests that modify debug settings (e.g., enabling SSH),...
CVE-2026-40434HIGH8.1Anviz CrossChex Standard lacks source verification in the client/server channel, enabling TCP packet injection by an at...
CVE-2026-40342CRITICAL9.9Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the exte...
CVE-2026-40283HIGH7.6WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vul...
CVE-2026-40066HIGH8.8Anviz CX2 Lite and CX7 are vulnerable to unverified update packages that can be uploaded. The device unpacks and execute...
CVE-2026-35682HIGH8.8Anviz CX2 Lite is vulnerable to an authenticated command injection via a filename parameter that enables arbitrary comm...
CVE-2026-35546CRITICAL9.8Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted,...
CVE-2026-35215HIGH7.5Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the sdl_...
CVE-2026-35061MEDIUM5.3Anviz CX7 Firmware is vulnerable to the most recently captured test photo that can be retrieved without authentication,...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now