2026 CVE Vulnerabilities

67,062 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-29597MEDIUM6.5DDSN Interactive cm3 Acora CMS version 10.7.1 contains an improper access control vulnerability. An editor-privileged us...
CVE-2026-21712MEDIUM6.5A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malform...
CVE-2026-5165HIGH7.8A flaw was found in virtio-win, specifically within the VirtIO Block (BLK) device. When the device undergoes a reset, it...
CVE-2026-5164MEDIUM5.5A flaw was found in virtio-win. The `RhelDoUnMap()` function does not properly validate the number of descriptors provid...
CVE-2026-5122MEDIUM6.3A security flaw has been discovered in osrg GoBGP up to 4.3.0. This affects the function DecodeFromBytes of the file pkg...
CVE-2026-33373HIGH8.8An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery (CSRF) vulnerability e...
CVE-2026-30566MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-30565MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-30564MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-30563MEDIUM6.1A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerabi...
CVE-2026-30082MEDIUM6.1Multiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngE...
CVE-2026-3321HIGH8.7A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1/answer/{EVENTID}/{TIME...
CVE-2026-28528MEDIUM4.6BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Browsing Target GET...
CVE-2026-28527HIGH7.3BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller GET_PLAY...
CVE-2026-28526MEDIUM5.7BlueKitchen BTstack versions prior to 1.8.1 contain an out-of-bounds read vulnerability in the AVRCP Controller LIST_PLA...
CVE-2026-4315MEDIUM6.5A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to t...
CVE-2026-4266MEDIUM6.7An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to...
CVE-2026-4425——Rejected reason: Reserved for EastLink case, but no need for CVE anymore
CVE-2026-1612MEDIUM6.9AL-KO Robolinho Update Software has hard-coded AWS Access and Secret keys that allow anyone to access AL-KO's AWS bucket...
CVE-2026-5128——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-5121HIGH7.5A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer ...
CVE-2026-4416HIGH8.5The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticate...
CVE-2026-4415CRITICAL9.8Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is ena...
CVE-2026-3945HIGH8.7An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version ...
CVE-2026-2328HIGH7.5An unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their i...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now