2026 CVE Vulnerabilities

68,230 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-32841CRITICAL9.2Edimax GS-5008PL firmware versions 1.00.54 and prior contain an authentication bypass vulnerability that allows unauthen...
CVE-2026-32840MEDIUM5.4Edimax GS-5008PL firmware version 1.00.54 and prior contain a stored cross-site scripting vulnerability in the system_na...
CVE-2026-32839MEDIUM6.5Edimax GS-5008PL firmware version 1.00.54 and prior contain a cross-site request forgery vulnerability that allows remot...
CVE-2026-32838MEDIUM5.9Edimax GS-5008PL firmware version 1.00.54 and prior use cleartext HTTP for the web management interface without implemen...
CVE-2026-1376HIGH7.5IBM i 7.6 could allow a remote attacker to cause a denial of service using failed authentication connections due to impr...
CVE-2026-1267MEDIUM6.5IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an unauthorized access to sensitive application data and a...
CVE-2026-2809MEDIUM6.7Netskope was notified about a potential gap in its Endpoint DLP Module for Netskope Client on Windows systems. The succe...
CVE-2026-4359LOW3.7A compromised third party cloud server or man-in-the-middle attacker could send a malformed HTTP response and cause a cr...
CVE-2026-4358HIGH7.5A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-fre...
CVE-2026-4295HIGH8.5Improper trust boundary enforcement in Kiro IDE before version 0.8.0 on all supported platforms might allow a remote una...
CVE-2026-4064HIGH8.3Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authen...
CVE-2026-3563MEDIUM5.5Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an auth...
CVE-2026-32981HIGH7.5A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due t...
CVE-2026-32837MEDIUM5.1miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vulnerabi...
CVE-2026-32836MEDIUM6.9dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled me...
CVE-2026-30707HIGH8.1An issue was discovered in SpeedExam Online Examination System (SaaS) after v.FEV2026. It allows Broken Access Control v...
CVE-2026-25936HIGH8.8GLPI is a free Asset and IT management software package. Starting in version 11.0.0 and prior to version 11.0.6, an auth...
CVE-2026-3207CRITICAL9.8Configuration issue in Java Management Extensions (JMX) in TIBCO BPM Enterprise version 4.x allows unauthorised access.
CVE-2026-25790HIGH7.2Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 ...
CVE-2026-25772HIGH7.2Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 ...
CVE-2026-25771HIGH7.5Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.3.0 ...
CVE-2026-22882HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2026-20726HIGH7.1An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF ...
CVE-2026-4319CRITICAL9.8A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unkno...
CVE-2026-32298CRITICAL9.1The Angeet ES3 KVM does not properly sanitize user-supplied variables parsed by the 'cfg.lua' script, allowing an authen...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now