2026 CVE Vulnerabilities

67,245 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33688MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `o...
CVE-2026-33685MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/AD_Server/reports.json.p...
CVE-2026-33683MEDIUM5.4WWBN AVideo is an open source video platform. In versions up to and including 26.0, a sanitization order-of-operations f...
CVE-2026-33681HIGH7.2WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginRunDatabaseScript...
CVE-2026-33651HIGH8.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `remindMe.json.php` endpoint pas...
CVE-2026-33650HIGH7.6WWBN AVideo is an open source video platform. In versions up to and including 26.0, a user with the "Videos Moderator" p...
CVE-2026-33649HIGH8.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermissio...
CVE-2026-33648HIGH8.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer endpoint constructs a...
CVE-2026-33647HIGH8.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `ImageGallery::saveFile()` metho...
CVE-2026-33513HIGH7.5WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`AP...
CVE-2026-33512HIGH7.5WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptStr...
CVE-2026-26209HIGH7.5cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Versions ...
CVE-2026-25075HIGH8.7strongSwan versions 4.5.0 prior to 6.0.5 contain an integer underflow vulnerability in the EAP-TTLS AVP parser that allo...
CVE-2026-0898CRITICAL9An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are autom...
CVE-2026-4594HIGH7.3A vulnerability has been found in erupts erupt up to 1.13.3. Affected by this issue is the function geneEruptHqlOrderBy ...
CVE-2026-4593MEDIUM6.3A flaw has been found in erupts erupt bis 1.13.3. Affected by this vulnerability is the function EruptDataQuery of the f...
CVE-2026-33507HIGH8.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` ...
CVE-2026-33502HIGH8.2WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side reque...
CVE-2026-33501MEDIUM5.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/Vie...
CVE-2026-33500MEDIUM5.4WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcq...
CVE-2026-33499MEDIUM6.1WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbiddenPage.php` and `vi...
CVE-2026-30007MEDIUM6.2XnSoft NConvert 7.230 is vulnerable to Use-After-Free via a crafted .tiff file
CVE-2026-30006MEDIUM6.2XnSoft NConvert 7.230 is vulnerable to Stack Buffer Overrun via a crafted .tiff file.
CVE-2026-26829HIGH7.5A NULL pointer dereference in the safe_atou64 function (src/misc.c) of owntone-server through commit c4d57aa allows atta...
CVE-2026-26828HIGH7.5A NULL pointer dereference in the daap_reply_playlists function (src/httpd_daap.c) of owntone-server commit 3d1652d allo...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now