2026 CVE Vulnerabilities

68,738 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-78668——Rejected reason: reserved but not needed
CVE-2026-76949CRITICAL9.1Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who can plant a re...
CVE-2026-73639CRITICAL9.1Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tR...
CVE-2026-73638MEDIUM6.2Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_...
CVE-2026-54767CRITICAL9.1WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php...
CVE-2026-54734CRITICAL10Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-suppl...
CVE-2026-54671HIGH8.8WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource arra...
CVE-2026-54670CRITICAL9.1WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/cont...
CVE-2026-54648MEDIUM6.5CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR tools in admin/sources/customers.gdpr.inc.php rely ...
CVE-2026-54647HIGH7.2CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates t...
CVE-2026-54646HIGH7.2CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places administrator...
CVE-2026-54645MEDIUM4.8CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, ...
CVE-2026-54644MEDIUM6.1CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip...
CVE-2026-54643MEDIUM5.4CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.ph...
CVE-2026-54642MEDIUM5.3CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-...
CVE-2026-54634HIGH7.3Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld ...
CVE-2026-54633MEDIUM6.9PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed col...
CVE-2026-54613MEDIUM5.4Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5...
CVE-2026-54612HIGH8.8Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until...
CVE-2026-54608HIGH7.1MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/Syste...
CVE-2026-54520HIGH8.1AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior ...
CVE-2026-54519HIGH8.8AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior ...
CVE-2026-54507HIGH8.4Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5...
CVE-2026-54506HIGH7.6Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5...
CVE-2026-54343HIGH8.7Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now