2026 CVE Vulnerabilities

67,111 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-34368MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `p...
CVE-2026-34364MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint, ...
CVE-2026-30568MEDIUM4.8A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in in the v...
CVE-2026-30567MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view...
CVE-2026-4964MEDIUM6.5A security vulnerability has been detected in letta-ai letta 0.16.4. This vulnerability affects the function _convert_me...
CVE-2026-4963CRITICAL10A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evalu...
CVE-2026-4962HIGH7A security flaw has been discovered in UltraVNC up to 1.6.4.0. Affected by this issue is some unknown functionality in t...
CVE-2026-4961HIGH8.8A vulnerability was identified in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formQuickIndex o...
CVE-2026-4960HIGH8.8A vulnerability was determined in Tenda AC6 15.03.05.16. Affected is the function fromWizardHandle of the file /goform/W...
CVE-2026-34411MEDIUM6.9Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticat...
CVE-2026-34362MEDIUM5.4WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function i...
CVE-2026-34247MEDIUM5.4WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live/uploadPoster.php` e...
CVE-2026-34245MEDIUM6.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists...
CVE-2026-33867HIGH7.5WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to pass...
CVE-2026-33770CRITICAL9.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method ...
CVE-2026-33767HIGH8.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, in `objects/like.php`, the `getLike(...
CVE-2026-30576HIGH7.5A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file...
CVE-2026-30575HIGH7.5A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file...
CVE-2026-30574HIGH7.5A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file...
CVE-2026-30571MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view...
CVE-2026-30570MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view...
CVE-2026-30569MEDIUM6.1A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulner...
CVE-2026-28369CRITICAL9.1A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more...
CVE-2026-28368CRITICAL9.1A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where ...
CVE-2026-28367CRITICAL9.1A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block ter...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now