2026 CVE Vulnerabilities

67,248 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33297CRITICAL9.1WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the Customiz...
CVE-2026-4588LOW3.7A vulnerability was determined in kalcaddle kodbox 1.64. Impacted is the function shareSafeGroup of the file /workspace/...
CVE-2026-4587MEDIUM6.3A vulnerability was found in HybridAuth up to 3.12.2. This issue affects some unknown processing of the file src/HttpCli...
CVE-2026-4586MEDIUM6.3A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects the function Upload of the file chat2db-serve...
CVE-2026-31851CRITICAL9.8Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout mec...
CVE-2026-31850MEDIUM4.9Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores sensitive information, including administrative ...
CVE-2026-31849MEDIUM6.5Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing e...
CVE-2026-31848CRITICAL9.8Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 uses the ecos_pw cookie for authentication, which conta...
CVE-2026-31847HIGH8.8Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.0...
CVE-2026-1958HIGH8.7Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an unauthorized attacker access to several i...
CVE-2026-4585CRITICAL9.8A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects u...
CVE-2026-4584LOW3.1A flaw has been found in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. This affects an unknown part of the component Car...
CVE-2026-32969HIGH7.5An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s a...
CVE-2026-32968CRITICAL9.8Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exp...
CVE-2026-31846HIGH7.1Missing authentication in the /goform/ate endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 a...
CVE-2026-4633LOW3.7A flaw was found in Keycloak. A remote attacker can exploit differential error messages during the identity-first login ...
CVE-2026-4583MEDIUM5A vulnerability was detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this issue is some unknown fun...
CVE-2026-28809MEDIUM5.3XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local fi...
CVE-2026-4582MEDIUM5A security vulnerability has been detected in Shenzhen HCC Technology MPOS M6 PLUS 1V.31-N. Affected by this vulnerabili...
CVE-2026-4581CRITICAL9.8A weakness has been identified in code-projects Simple Laundry System 1.0. Affected is an unknown function of the file /...
CVE-2026-4628MEDIUM4.3A flaw was found in Keycloak. An improper Access Control vulnerability in Keycloak’s User-Managed Access (UMA) resource_...
CVE-2026-4580CRITICAL9.8A security flaw has been discovered in code-projects Simple Laundry System 1.0. This impacts an unknown function of the ...
CVE-2026-4579CRITICAL9.8A vulnerability was identified in code-projects Simple Laundry System 1.0. This affects an unknown function of the file ...
CVE-2026-4578LOW2.4A vulnerability was determined in code-projects Exam Form Submission 1.0. The impacted element is an unknown function of...
CVE-2026-3587CRITICAL10An unauthenticated remote attacker can exploit a hidden function in the CLI prompt to escape the restricted interface, l...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now