2026 CVE Vulnerabilities

66,723 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34395MEDIUM6.5WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/YPTWallet/view/users.json.php endpo...
CVE-2026-34394HIGH8.1WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's admin plugin configuration endpoint (...
CVE-2026-34384HIGH7.3Admidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_u...
CVE-2026-34383LOW3.5Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint ac...
CVE-2026-34382MEDIUM4.6Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, the delete mode handler ...
CVE-2026-34381HIGH7.5Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, Admidio relies on adm_my...
CVE-2026-34372LOW2.7Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.2...
CVE-2026-34367HIGH8.7InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and...
CVE-2026-34366HIGH8.1InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and...
CVE-2026-1579CRITICAL9.8The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message s...
CVE-2026-5211HIGH8.8A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, D...
CVE-2026-4800CRITICAL9.8Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variabl...
CVE-2026-34784HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34365HIGH8.1InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and...
CVE-2026-34215MEDIUM6.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-34206MEDIUM6.1Captcha Protect is a Traefik middleware to add an anti-bot challenge to individual IPs in a subnet when traffic spikes a...
CVE-2026-34204HIGH7.1MinIO is a high-performance object storage system. Prior to version RELEASE.2026-03-26T21-24-40Z, a flaw in extractMetad...
CVE-2026-34203MEDIUM4.3Nautobot is a Network Source of Truth and Network Automation Platform. Prior to versions 2.4.30 and 3.0.10, user creatio...
CVE-2026-30290HIGH8.4An arbitrary file overwrite vulnerability in InTouch Contacts & Caller ID APP v6.38.1 allows attackers to overwrite crit...
CVE-2026-30285CRITICAL9.8An arbitrary file overwrite vulnerability in Zora: Post, Trade, Earn Crypto v2.60.0 allows attackers to overwrite critic...
CVE-2026-30280MEDIUM5.3An arbitrary file overwrite vulnerability in RAREPROB SOLUTIONS PRIVATE LIMITED Video player Play All Videos v1.0.135 al...
CVE-2026-2950MEDIUM5.3Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. ...
CVE-2026-5210HIGH7.3A vulnerability was detected in SourceCodester Leave Application System 1.0. This affects an unknown part. Performing a ...
CVE-2026-5209LOW2.4A security vulnerability has been detected in SourceCodester Leave Application System 1.0. Affected by this issue is som...
CVE-2026-3356CRITICAL9.3The MS27102A Remote Spectrum Monitor is vulnerable to an authentication bypass that allows unauthorized users to access ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now