2026 CVE Vulnerabilities

67,248 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-81469HIGH7.8Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A l...
CVE-2026-79320MEDIUM6.1Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime. When a downs...
CVE-2026-79319MEDIUM5.3Stencil core 4.43.5 is vulnerable to Incorrect Access Control.
CVE-2026-79318MEDIUM6.5web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file(...
CVE-2026-73552HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-73550HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-73549MEDIUM5.3Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-73548HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-73547HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-73546HIGH7.4Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-73513HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-73512HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-62247MEDIUM6.5Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authoriz...
CVE-2026-58271MEDIUM6.8Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0,...
CVE-2026-58269HIGH8.1Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0,...
CVE-2026-55897HIGH8.8luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router in...
CVE-2026-55159HIGH8.8luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, ...
CVE-2026-54915MEDIUM5.4Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /aut...
CVE-2026-52835HIGH7Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the import_config handle...
CVE-2026-50572MEDIUM5.9Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-49995MEDIUM4.8Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the newsletter cron fiel...
CVE-2026-49811HIGH8.4Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resourc...
CVE-2026-48521MEDIUM5.9Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-45381MEDIUM5.1Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint ins...
CVE-2026-94501HIGH8.8jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authent...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now