2026 CVE Vulnerabilities

46,863 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-0287HIGH7.5Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with...
CVE-2026-0286HIGH7.2A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticate...
CVE-2026-0283HIGH7.2An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software a...
CVE-2026-0281HIGH7.1An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with ...
CVE-2026-0280HIGH7.2An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticat...
CVE-2026-61343HIGH8.6LibreBooking's email template editor save action passes the submitted template name directly into the destination file p...
CVE-2026-59827HIGH8.8Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1...
CVE-2026-59734HIGH8.8Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta....
CVE-2026-59721HIGH7.2Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in ad...
CVE-2026-59720HIGH7.5Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.t...
CVE-2026-59221HIGH7.7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _sanitiz...
CVE-2026-58378HIGH8.8Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB a...
CVE-2026-55420HIGH8.1Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, under certain non-...
CVE-2026-59224HIGH8Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webu...
CVE-2026-59219HIGH7.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0 with Redi...
CVE-2026-53987HIGH7.3The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sanitization and renders it into the Kanban ba...
CVE-2026-51606HIGH7.5An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device t...
CVE-2026-51605HIGH7.5A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unaut...
CVE-2026-51604HIGH7.5A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth...
CVE-2026-51603HIGH7.5A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth...
CVE-2026-51602HIGH7.5A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauth...
CVE-2026-51601HIGH7.5Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to valid...
CVE-2026-51600HIGH7.5Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIB...
CVE-2026-15308HIGH7.5The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark...
CVE-2026-15190HIGH7.3A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now