2026 CVE Vulnerabilities

65,063 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-39906CRITICAL10Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel t...
CVE-2026-35196HIGH8.8Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Command Injection vulne...
CVE-2026-34631HIGH7.8InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbit...
CVE-2026-34619HIGH7.7ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir...
CVE-2026-34602HIGH7.1Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the /api/course_rel_users end...
CVE-2026-34370MEDIUM6.5Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the notebook module contains ...
CVE-2026-34213MEDIUM5.4Docmost is open-source collaborative wiki and documentation software. Starting in version 0.3.0 and prior to version 0.7...
CVE-2026-34212MEDIUM5.4Docmost is open-source collaborative wiki and documentation software. In versions prior to 0.71.0, improper neutralizati...
CVE-2026-33193MEDIUM4.6Docmost is open-source collaborative wiki and documentation software. Versions prior to 0.70.0 are vulnerable to a store...
CVE-2026-33146MEDIUM4.3Docmost is open-source collaborative wiki and documentation software. An authorization bypass vulnerability in versions ...
CVE-2026-33020HIGH7.1libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integ...
CVE-2026-33019HIGH7.1libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain an integ...
CVE-2026-33018HIGH7libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. Versions 1.8.7 and prior contain a Use-Af...
CVE-2026-27308LOW2.4ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that ...
CVE-2026-27307LOW2.4ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that ...
CVE-2026-27306HIGH8.4ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-27305HIGH8.6ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir...
CVE-2026-27304CRITICAL9.3ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-27282HIGH7.5ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could re...
CVE-2026-34161MEDIUM5.4Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, a Stored Cross-Site Scripting...
CVE-2026-34160HIGH8.6Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange No...
CVE-2026-33715HIGH7.2Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.aja...
CVE-2026-33714HIGH7.2Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in...
CVE-2026-27287HIGH7.8InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file...
CVE-2026-25133MEDIUM4.8October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cros...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now