2026 CVE Vulnerabilities

70,292 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-3224CRITICAL9.8Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and ear...
CVE-2026-3204CRITICAL9.8Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers...
CVE-2026-3130CRITICAL9.8Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker...
CVE-2026-2590CRITICAL9.8Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions...
CVE-2026-27012CRITICAL9.8OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a pri...
CVE-2026-25146HIGH8.1OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to b...
CVE-2026-24898CRITICAL9.8OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0,...
CVE-2026-24848CRITICAL9.9OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and ea...
CVE-2026-24415MEDIUM6.1OpenSTAManager is an open source management software for technical assistance and invoicing. OpenSTAManager v2.9.8 and e...
CVE-2026-21866MEDIUM5.4Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rend...
CVE-2026-1775HIGH8.8The Labkotec LID-3300IP has an existing vulnerability in the ice detector software that enables an unauthenticated attac...
CVE-2026-3486HIGH7.2A vulnerability has been found in itsourcecode College Management System 1.0. This vulnerability affects unknown code of...
CVE-2026-3485CRITICAL9.8A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This...
CVE-2026-25906HIGH7.8Dell Optimizer, versions prior to 6.3.1, contain an Improper Link Resolution Before File Access ('Link Following') vulne...
CVE-2026-24502HIGH7.8Dell Command | Intel vPro Out of Band, versions prior to 4.7.0, contain an Uncontrolled Search Path Element vulnerabilit...
CVE-2026-1713MEDIUM5IBM MQ 9.1.0.0 through 9.1.0.33 LTS, 9.2.0.0 through 9.2.0.40 LTS, 9.3.0.0 through 9.3.0.36 LTS, 9.30.0 through 9.3.5.1 ...
CVE-2026-1567HIGH7.5IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere...
CVE-2026-3494MEDIUM5.3In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configur...
CVE-2026-3484HIGH8.8A vulnerability was detected in PhialsBasement nmap-mcp-server up to bee6d23547d57ae02460022f7c78ac0893092e38. Affected ...
CVE-2026-2915HIGH7.1HP System Event Utility might allow denial of service with elevated arbitrary file writes. This potential vulnerability ...
CVE-2026-2606MEDIUM6.5IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API M...
CVE-2026-29022HIGH7.8dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in th...
CVE-2026-26892HIGH7.2Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_carrier.php.
CVE-2026-26891LOW2.7Sourcecodester Logistic Hub Parcel's Management System v1.0 is vulnerable to SQL Injection in /manage_parcel_type.php.
CVE-2026-26889LOW2.7Sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_category.php.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now