2026 CVE Vulnerabilities

70,008 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-29046HIGH8.2TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.04, TinyWeb accepts request header...
CVE-2026-29041HIGH8.8Chamilo is a learning management system. Prior to version 1.11.34, Chamilo LMS is affected by an authenticated remote co...
CVE-2026-28502HIGH8.8WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulner...
CVE-2026-28501CRITICAL9.8WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exis...
CVE-2026-28497CRITICAL9.1TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. Prior to version 2.03, an integer overflow vulnerabil...
CVE-2026-27807MEDIUM4.9MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs allows...
CVE-2026-25962MEDIUM6.5MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs curren...
CVE-2026-3616MEDIUM6.3A vulnerability was detected in DefaultFuction Jeson Customer Relationship Management System 1.0.0. Impacted is an unkno...
CVE-2026-3613HIGH7.3A vulnerability was identified in Wavlink WL-NU516U1 V240425. This vulnerability affects the function sub_401A0C of the ...
CVE-2026-3612HIGH7.3A vulnerability was determined in Wavlink WL-NU516U1 V240425. This affects the function sub_405AF4 of the file /cgi-bin/...
CVE-2026-3610MEDIUM4.3A vulnerability was found in HSC Cybersecurity Mailinspector up to 5.3.2-3. Affected by this issue is some unknown funct...
CVE-2026-2589MEDIUM5.3The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Sensitive Information Exposure ...
CVE-2026-28727HIGH7.8Local privilege escalation due to insecure Unix socket permissions. The following products are affected: Acronis Cyber P...
CVE-2026-28726MEDIUM4.3Sensitive information disclosure due to improper access control. The following products are affected: Acronis Cyber Prot...
CVE-2026-28725MEDIUM5.5Sensitive information disclosure due to improper configuration of a headless browser. The following products are affecte...
CVE-2026-28724MEDIUM4.3Unauthorized data access due to insufficient access control validation. The following products are affected: Acronis Cyb...
CVE-2026-28723MEDIUM4.3Unauthorized report deletion due to insufficient access control. The following products are affected: Acronis Cyber Prot...
CVE-2026-28722HIGH7.3Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec...
CVE-2026-28721HIGH7.3Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec...
CVE-2026-28720MEDIUM4.3Unauthorized modification of settings due to insufficient authorization checks. The following products are affected: Acr...
CVE-2026-28719MEDIUM4.3Unauthorized resource manipulation due to improper authorization checks. The following products are affected: Acronis Cy...
CVE-2026-28718HIGH7.5Denial of service due to insufficient input validation in authentication logging. The following products are affected: A...
CVE-2026-28717MEDIUM5Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Pro...
CVE-2026-28716MEDIUM4.4Information disclosure and manipulation due to improper authorization checks. The following products are affected: Acron...
CVE-2026-28715MEDIUM6.5Sensitive information disclosure due to improper authorization checks. The following products are affected: Acronis Cybe...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now