2026 CVE Vulnerabilities

67,245 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-24516HIGH8.8A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner compo...
CVE-2026-4592MEDIUM5.6A security vulnerability has been detected in kalcaddle kodbox 1.64. This impacts the function loginAfter/tfaVerify of t...
CVE-2026-4591MEDIUM4.7A weakness has been identified in kalcaddle kodbox 1.64. This affects the function checkBin of the file /workspace/sourc...
CVE-2026-33493HIGH8.1WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/import.json.php` endpoi...
CVE-2026-33492HIGH7.3WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function...
CVE-2026-33488HIGH8.1WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the L...
CVE-2026-32845HIGH8.4cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when validating ...
CVE-2026-4590LOW3.1A security flaw has been discovered in kalcaddle kodbox 1.64. The impacted element is an unknown function of the file /w...
CVE-2026-4404CRITICAL9.4Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password ...
CVE-2026-33485HIGH7.5WWBN AVideo is an open source video platform. In versions up to and including 26.0, the RTMP `on_publish` callback at `p...
CVE-2026-33483HIGH7.5WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncoderChunk.json.php` en...
CVE-2026-33482HIGH8.1WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` functi...
CVE-2026-33480HIGH8.6WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeURL()` function in AV...
CVE-2026-33479HIGH8.8WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plugin's `saveSort.json....
CVE-2026-33478CRITICAL10WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's...
CVE-2026-33354MEDIUM6.5WWBN AVideo is an open source video platform. In versions up to and including 26.0, `POST /objects/aVideoEncoder.json.ph...
CVE-2026-4647MEDIUM6.1A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files...
CVE-2026-4645——Rejected reason: Duplicate of CVE-2026-32287
CVE-2026-4589MEDIUM6.3A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file ...
CVE-2026-3635MEDIUM6.1Summary When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0.0.1'...
CVE-2026-33352CRITICAL9.8WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exis...
CVE-2026-33351CRITICAL9.1WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability ...
CVE-2026-33297CRITICAL9.1WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the Customiz...
CVE-2026-4588LOW3.7A vulnerability was determined in kalcaddle kodbox 1.64. Impacted is the function shareSafeGroup of the file /workspace/...
CVE-2026-4587MEDIUM6.3A vulnerability was found in HybridAuth up to 3.12.2. This issue affects some unknown processing of the file src/HttpCli...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now