2026 CVE Vulnerabilities

66,711 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4829MEDIUM5.4Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an ...
CVE-2026-4828HIGH8.2Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote att...
CVE-2026-35099HIGH7.4Lakeside SysTrack Agent 11 before 11.5.0.15 has a race condition with resultant local privilege escalation to SYSTEM. Th...
CVE-2026-34510MEDIUM6.9OpenClaw before 2026.3.22 contains a path traversal vulnerability in Windows media loaders that accepts remote-host file...
CVE-2026-31027CRITICAL9.8TOTOlink A3600R v5.9c.4959 contains a buffer overflow vulnerability in the setAppEasyWizardConfig interface of /lib/cste...
CVE-2026-30573HIGH7.5A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is loc...
CVE-2026-30526MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Zoo Management System v1.0. The vulnerabil...
CVE-2026-30523MEDIUM6.5A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input vali...
CVE-2026-30292HIGH8.4An arbitrary file overwrite vulnerability in Docudepot PDF Reader: PDF Viewer APP v1.0.34 allows attackers to overwrite ...
CVE-2026-30291HIGH8.4An arbitrary file overwrite vulnerability in Ora Tools PDF Reader ' Reader & Editor APPv4.3.5 allows attackers to overwr...
CVE-2026-29598MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in the submit_add_user.asp endpoint of DDSN Interactive Acora...
CVE-2026-5271HIGH7.8pymanager included the current working directory in sys.path meaning modules could be shadowed by modules in the current...
CVE-2026-3877MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution a...
CVE-2026-35094MEDIUM5.5A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can expl...
CVE-2026-35093HIGH8.8A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or ...
CVE-2026-35092HIGH7.5A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a re...
CVE-2026-35091HIGH8.2A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Co...
CVE-2026-34999MEDIUM6.9OpenViking versions 0.2.5 prior to 0.2.14 contain a missing authentication vulnerability in the bot proxy router that al...
CVE-2026-34430CRITICAL9.6ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that al...
CVE-2026-30522MEDIUM6.5A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validati...
CVE-2026-30289HIGH8.4An arbitrary file overwrite vulnerability in Tinybeans Private Family Album App v5.9.5-prod allows attackers to overwrit...
CVE-2026-30287HIGH8.4An arbitrary file overwrite vulnerability in Deep Thought Industries ACE Scanner PDF Scanner v1.4.5 allows attackers to ...
CVE-2026-0522HIGH8.8A local file inclusion vulnerability in the upload/download flow of the VertiGIS FM application allows authenticated att...
CVE-2026-29014CRITICAL9.8MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote at...
CVE-2026-22768HIGH7.3Dell AppSync, version(s) 4.6.0, contain(s) an Incorrect Permission Assignment for Critical Resource vulnerability. A low...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now