2026 CVE Vulnerabilities

45,376 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-59221HIGH7.7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _sanitiz...
CVE-2026-58378HIGH8.8Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB a...
CVE-2026-55420HIGH8.1Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-...
CVE-2026-59224HIGH8Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webu...
CVE-2026-59219HIGH7.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0 with Redi...
CVE-2026-53987HIGH7.3The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sanitization and renders it into the Kanban ba...
CVE-2026-51606HIGH7.5An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device t...
CVE-2026-51605HIGH7.5A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unaut...
CVE-2026-51604HIGH7.5A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth...
CVE-2026-51603HIGH7.5A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth...
CVE-2026-51602HIGH7.5A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth...
CVE-2026-51601HIGH7.5Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to valid...
CVE-2026-51600HIGH7.5Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIB...
CVE-2026-15308HIGH7.5The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark...
CVE-2026-15190HIGH7.3A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of...
CVE-2026-13462HIGH7.5PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to ...
CVE-2026-59206HIGH7.1n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with t...
CVE-2026-11404HIGH8.7Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello...
CVE-2026-60109HIGH8.7Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauth...
CVE-2026-60108HIGH8.7Zeek before 8.0.9 contains an uncontrolled memory consumption vulnerability in the FTP analyzer that allows unauthentica...
CVE-2026-56292HIGH7.5Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing...
CVE-2026-54801HIGH8.6A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst...
CVE-2026-54799HIGH8.4A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst...
CVE-2026-54798HIGH7.1A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst...
CVE-2026-4256HIGH8.2Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now