2026 CVE Vulnerabilities

70,367 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-28360MEDIUM5.3NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, shared view passwords were stored i...
CVE-2026-28359MEDIUM5.4NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, an authenticated user with Editor r...
CVE-2026-28358MEDIUM5.3NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password forgot endpoint return...
CVE-2026-28357MEDIUM5.4NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, a stored XSS vulnerability exists i...
CVE-2026-28286CRITICAL9.9ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, t...
CVE-2026-26708CRITICAL9.8sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php.
CVE-2026-26700CRITICAL9.8sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_employee.php.
CVE-2026-24105CRITICAL9.8An issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not check...
CVE-2026-23865MEDIUM5.3An integer overflow in the tt_var_load_item_variation_store function of the Freetype library in versions 2.13.2 and 2.13...
CVE-2026-21385HIGH7.8Memory corruption while using alignments for memory allocation.
CVE-2026-28412HIGH7.5Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server imposes no limi...
CVE-2026-28403HIGH7.6Textream is a free macOS teleprompter app. Prior to version 1.5.1, the `DirectorServer` WebSocket server (`ws://127.0.0....
CVE-2026-26720CRITICAL9.8An issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts mod...
CVE-2026-26701CRITICAL9.8sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_tecnical_user...
CVE-2026-26699HIGH7.2sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin...
CVE-2026-24112CRITICAL9.8An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may exploit the vulnerability by specifying the value...
CVE-2026-24110CRITICAL9.8An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may send overly long `addDhcpRules` data. When these ...
CVE-2026-24101CRITICAL9.8An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` wi...
CVE-2026-0689MEDIUM4.9In ExtremeCloud IQ – Site Engine (XIQ‑SE) before 26.2.10, a vulnerability in the NAC administration interface allows an ...
CVE-2026-26703CRITICAL9.8sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/advance_search.php...
CVE-2026-26702CRITICAL9.8sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/myitem_reuse.php.
CVE-2026-26696CRITICAL9.8code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php.
CVE-2026-26695CRITICAL9.8code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php.
CVE-2026-26694CRITICAL9.8code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php.
CVE-2026-24115CRITICAL9.8An issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the sizes of `gstup` and `gstdwn` before co...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now