2026 CVE Vulnerabilities

65,813 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-5661MEDIUM5.5A vulnerability was identified in Free5GC 4.2.0. This affects an unknown function of the component NGSetupRequest Handle...
CVE-2026-34897MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Medi...
CVE-2026-34885HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi...
CVE-2026-33540HIGH7.5Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mod...
CVE-2026-33510HIGH8.8Homarr is an open-source dashboard. Prior to 1.57.0, a DOM-based Cross-Site Scripting (XSS) vulnerability has been disco...
CVE-2026-33406MEDIUM6.1Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic...
CVE-2026-33404MEDIUM6.1Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic...
CVE-2026-33403MEDIUM6.1Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level ad and internet tracker blocking applic...
CVE-2026-32602MEDIUM4.2Homarr is an open-source dashboard. Prior to 1.57.0, the user registration endpoint (/api/trpc/user.register) is vulnera...
CVE-2026-31153MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Bynder before 12 January 2026 allows attackers to execute arbitrary...
CVE-2026-31151CRITICAL9.8An issue in the login mechanism of Kaleris YMS v7.2.2.1 allows attackers to bypass login verification to access the appl...
CVE-2026-31150MEDIUM4.3Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to...
CVE-2026-31067MEDIUM6.8A remote command execution (RCE) vulnerability in the /goform/formReleaseConnect component of UTT Aggressive 520W v3v1.7...
CVE-2026-31066MEDIUM4.5UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the selDateType parameter of th...
CVE-2026-31065MEDIUM4.5UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the addCommand parameter of the formC...
CVE-2026-31063MEDIUM4.5UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the pools parameter of the form...
CVE-2026-31062MEDIUM4.5UTT Aggressive 520W v3v1.7.7-180627 was discovered to contain a buffer overflow in the filename parameter of the formFtp...
CVE-2026-31061MEDIUM4.5UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the timestart parameter of the ...
CVE-2026-31060MEDIUM4.5UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the notes parameter of the form...
CVE-2026-31059CRITICAL9.8A remote command execution (RCE) vulnerability in the /goform/formDia component of UTT Aggressive HiPER 520W v3v1.7.7-18...
CVE-2026-31058MEDIUM4.5UTT Aggressive HiPER 1200GW v2.5.3-170306 was discovered to contain a buffer overflow in the timeRangeName parameter of ...
CVE-2026-31053MEDIUM6.2A double free vulnerability exists in librz/bin/format/le/le.c in the function le_load_fixup_record(). When processing m...
CVE-2026-29047HIGH8.8GLPI is a free asset and IT management software package. From 10.0.0 to before 10.0.24 and 11.0.6, an authenticated user...
CVE-2026-26263CRITICAL9.8GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based bli...
CVE-2026-26027MEDIUM6.1GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated user can store...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now