2026 CVE Vulnerabilities

67,274 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-94107HIGH8.1NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that gene...
CVE-2026-94106HIGH8.8getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames ...
CVE-2026-94105MEDIUM5.3NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller t...
CVE-2026-94104HIGH8.8NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails t...
CVE-2026-94004HIGH7.3A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytag_j...
CVE-2026-94003CRITICAL10A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /c...
CVE-2026-93997HIGH7.3A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown ...
CVE-2026-93980HIGH7.3A weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown cod...
CVE-2026-93979HIGH7.3A security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown part of t...
CVE-2026-93978HIGH7.3A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown...
CVE-2026-93977LOW3.5A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown ...
CVE-2026-93976LOW2.4A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/...
CVE-2026-93975LOW2.4A vulnerability has been found in code-projects Assessment Management 1.0. This impacts an unknown function of the file ...
CVE-2026-86555MEDIUM6.2The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plain...
CVE-2026-93974HIGH7.3A flaw has been found in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the f...
CVE-2026-93973HIGH7.3A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown...
CVE-2026-93972HIGH7.3A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element...
CVE-2026-93971MEDIUM5.3A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevo...
CVE-2026-93970HIGH7.3A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the fil...
CVE-2026-86554MEDIUM4.3SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process...
CVE-2026-93969HIGH7.3A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_sup...
CVE-2026-93968LOW3.8A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/...
CVE-2026-93967MEDIUM5.5A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this issue is the function generate_host_task of th...
CVE-2026-93966MEDIUM4.7A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this vulnerability is the function paramiko.SS...
CVE-2026-92965LOW3.7The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code sup...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now