2026 CVE Vulnerabilities

69,114 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-4039HIGH8.8A vulnerability was determined in OpenClaw 2026.2.19-2. This vulnerability affects the function applySkillConfigenvOverr...
CVE-2026-3989HIGH7.8SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An at...
CVE-2026-3060CRITICAL9.8SGLang' encoder parallel disaggregation system is vulnerable to unauthenticated remote code execution through the disagg...
CVE-2026-3059CRITICAL9.8SGLang's multimodal generation module is vulnerable to unauthenticated remote code execution through the ZMQ broker, whi...
CVE-2026-3234MEDIUM4.3A flaw was found in mod_proxy_cluster. This vulnerability, a Carriage Return Line Feed (CRLF) injection in the decodeen...
CVE-2026-2366LOW3.1A flaw was found in Keycloak. An authorization bypass vulnerability in the Keycloak Admin API allows any authenticated u...
CVE-2026-4016MEDIUM5.3A security vulnerability has been detected in GPAC 26.03-DEV. Affected by this vulnerability is the function svgin_proce...
CVE-2026-4015MEDIUM5.3A weakness has been identified in GPAC 26.03-DEV. Affected is the function txtin_process_texml of the file src/filters/l...
CVE-2026-4014CRITICAL9.8A security flaw has been discovered in itsourcecode Cafe Reservation System 1.0. This impacts an unknown function of the...
CVE-2026-4013MEDIUM6.3A vulnerability was identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unkno...
CVE-2026-4012LOW3.3A vulnerability was determined in rxi fe up to ed4cda96bd582cbb08520964ba627efb40f3dd91. The impacted element is the fun...
CVE-2026-4010LOW3.3A vulnerability was found in ThakeeNathees pocketlang up to cc73ca61b113d48ee130d837a7a8b145e41de5ce. The affected eleme...
CVE-2026-4009LOW3.3A vulnerability has been found in jarikomppa soloud up to 20200207. Impacted is the function drwav_read_pcm_frames_s16__...
CVE-2026-4008HIGH8.8A flaw has been found in Tenda W3 1.0.0.3(2204). This issue affects some unknown processing of the file /goform/wifiSSID...
CVE-2026-4007HIGH8.8A vulnerability was detected in Tenda W3 1.0.0.3(2204). This vulnerability affects unknown code of the file /goform/wifi...
CVE-2026-3994MEDIUM5.3A vulnerability was detected in rui314 mold up to 2.40.4. This issue affects the function mold::ObjectFilemold::X86_64::...
CVE-2026-3993MEDIUM4.3A security vulnerability has been detected in itsourcecode Payroll Management System 1.0. This vulnerability affects unk...
CVE-2026-3992MEDIUM6.3A weakness has been identified in CodeGenieApp serverless-express up to 4.17.1. This affects an unknown part of the file...
CVE-2026-3990MEDIUM4.3A security flaw has been discovered in CesiumGS CesiumJS up to 1.137.0. Affected by this issue is some unknown functiona...
CVE-2026-3984LOW3.5A weakness has been identified in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This vulnerab...
CVE-2026-3983LOW3.5A security flaw has been discovered in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This aff...
CVE-2026-2687MEDIUM4.3The Reading progressbar WordPress plugin before 1.3.1 does not sanitise and escape some of its settings, which could all...
CVE-2026-3982MEDIUM4.3A vulnerability was determined in itsourcecode University Management System 1.0. Affected by this vulnerability is an un...
CVE-2026-3981CRITICAL9.8A vulnerability was found in itsourcecode Online Doctor Appointment System 1.0. Affected is an unknown function of the f...
CVE-2026-3980CRITICAL9.8A vulnerability has been found in itsourcecode Online Doctor Appointment System 1.0. This impacts an unknown function of...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now