2026 CVE Vulnerabilities

43,261 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-72606HIGH7.5A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the ...
CVE-2026-72605HIGH7.5A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary ...
CVE-2026-72602HIGH7.5A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attacke...
CVE-2026-72601HIGH7.5A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissi...
CVE-2026-72600HIGH7.5A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download...
CVE-2026-72596HIGH8.1A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete pos...
CVE-2026-72595HIGH8.1A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update tic...
CVE-2026-72563HIGH8.1A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite ...
CVE-2026-72562HIGH8.8An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users...
CVE-2026-72561HIGH8.8A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-a...
CVE-2026-72558HIGH8.8An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via...
CVE-2026-72557HIGH8.8An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extensi...
CVE-2026-72556HIGH8.8A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by expl...
CVE-2026-72555HIGH8.1A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.role...
CVE-2026-72552HIGH7.5A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the ...
CVE-2026-72551HIGH8.8A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to execute...
CVE-2026-72548HIGH7.5An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers ...
CVE-2026-72547HIGH7.1An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org...
CVE-2026-72546HIGH7.1An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event org...
CVE-2026-72545HIGH7.5An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote ...
CVE-2026-72544HIGH7.5An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers ...
CVE-2026-72543HIGH7.5An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote ...
CVE-2026-72538HIGH8.8An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code...
CVE-2026-72537HIGH8.8A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-s...
CVE-2026-72536HIGH8.6A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mani...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now