2026 CVE Vulnerabilities

67,113 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28368CRITICAL9.1A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where ...
CVE-2026-28367CRITICAL9.1A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block ter...
CVE-2026-4959HIGH7.5A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/applica...
CVE-2026-4958MEDIUM6.5A vulnerability has been found in OpenBMB XAgent 1.0.0. This affects the function ReplayServer.on_connect/ReplayServer.s...
CVE-2026-32984MEDIUM5.3Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed...
CVE-2026-32983HIGH7.5Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-i...
CVE-2026-30534HIGH8.3A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via...
CVE-2026-30533CRITICAL9.8A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php ...
CVE-2026-30532CRITICAL9.8A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php fi...
CVE-2026-30531HIGH8.8A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi...
CVE-2026-30530CRITICAL9.8A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi...
CVE-2026-30529HIGH8.8A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifi...
CVE-2026-30527MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Categ...
CVE-2026-30302CRITICAL10The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whiteli...
CVE-2026-5027HIGH8.8The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an a...
CVE-2026-5026MEDIUM5.4The '/api/v1/files/images/{flow_id}/{file_name}' endpoint serves SVG files with the 'image/svg+xml' content type without...
CVE-2026-5025MEDIUM6.5The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log...
CVE-2026-5022MEDIUM5.3The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, a...
CVE-2026-5010MEDIUM5.1A reflected Cross-Site Scripting (XSS) vulnerability has been discovered in Clickedu. This vulnerability allows an attac...
CVE-2026-4984HIGH8.2The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When ...
CVE-2026-4980MEDIUM6.3A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote at...
CVE-2026-4957LOW2.7A flaw has been found in OpenBMB XAgent 1.0.0. The impacted element is the function FunctionHandler.handle_tool_call of ...
CVE-2026-4956HIGH7.3A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. The affected element is an unknown f...
CVE-2026-4955HIGH7.3A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. This impacts an unknown function of the...
CVE-2026-4954MEDIUM6.3A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/m...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now