2026 CVE Vulnerabilities

65,056 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34232HIGH7.5Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the xdr_...
CVE-2026-33569MEDIUM6.5Anviz CX2 Lite and CX7 administrative sessions occur over HTTP, enabling on‑path attackers to sniff credentials and ses...
CVE-2026-33516CRITICAL9.1xrdp is an open source RDP server. Versions through 0.10.5 contain an out-of-bounds read vulnerability during the RDP ca...
CVE-2026-33093MEDIUM5.3Anviz CX7 Firmware is vulnerable to an unauthenticated POST to the device that captures a photo with the front facing c...
CVE-2026-32650HIGH7.5Anviz CrossChex Standard is vulnerable when an attacker manipulates the TDS7 PreLogin to disable encryption, causing da...
CVE-2026-32648MEDIUM5.3Anviz CX2 Lite and CX7 are vulnerable to unauthenticated access that discloses debug configuration details (e.g., SSH/R...
CVE-2026-32624MEDIUM6.5xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in its log...
CVE-2026-32623HIGH8.1xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in the Neu...
CVE-2026-32324HIGH7.7Anviz CX7 Firmware is  vulnerable because the application embeds reusable certificate/key material, enabling decryption...
CVE-2026-32107HIGH8.8xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle a...
CVE-2026-32105HIGH7.7xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Auth...
CVE-2026-31927MEDIUM4.9Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files...
CVE-2026-6437MEDIUM6.9Improper neutralization of argument delimiters in the volume handling component in AWS EFS CSI Driver (aws-efs-csi-drive...
CVE-2026-40525CRITICAL9.1OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route su...
CVE-2026-33337HIGH7.5Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when des...
CVE-2026-28224HIGH8.2Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the...
CVE-2026-28214MEDIUM6.5Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the Clum...
CVE-2026-28212HIGH7.5Firebird is an open-source relational database management system. In versions prior to 6.0.0, 5.0.4, 4.0.7 and 3.0.14, w...
CVE-2026-27890HIGH8.2Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when pro...
CVE-2026-5718HIGH8.1The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file upload in...
CVE-2026-5710HIGH7.5The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Path Traversal leading t...
CVE-2026-40320HIGH7.8Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the ConformityCheck class rende...
CVE-2026-40319MEDIUM5.5Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the RegexMatching check passes ...
CVE-2026-40518CRITICAL9.1ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerability in bootstrap-m...
CVE-2026-40516MEDIUM6.3OpenHarness before commit bd4df81 contains a server-side request forgery vulnerability in the web_fetch and web_search t...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now