2026 CVE Vulnerabilities

48,532 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-70559HIGH8.7Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation t...
CVE-2026-70558CRITICAL9.8Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) ...
CVE-2026-70557HIGH7.1diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of ...
CVE-2026-69125Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67321. Reason: This candidate is a ...
CVE-2026-69124Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67320. Reason: This candidate is a ...
CVE-2026-69123Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67319. Reason: This candidate is a ...
CVE-2026-68948Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67318. Reason: This candidate is a ...
CVE-2026-68947Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67317. Reason: This candidate is a ...
CVE-2026-68946Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67315. Reason: This candidate is a ...
CVE-2026-68944Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67316. Reason: This candidate is a ...
CVE-2026-68943Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67314. Reason: This candidate is a ...
CVE-2026-68942Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67313. Reason: This candidate is a ...
CVE-2026-68941Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67312. Reason: This candidate is a ...
CVE-2026-68480In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt in...
CVE-2026-67689CRITICAL9.8SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `or...
CVE-2026-67688CRITICAL9.8ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module....
CVE-2026-67687HIGH8.8Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/rol...
CVE-2026-67622CRITICAL9.9Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration th...
CVE-2026-67621HIGH7.6Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perf...
CVE-2026-67434HIGH7.3PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13....
CVE-2026-67422HIGH7.5pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, ...
CVE-2026-65400CRITICAL9.8An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS...
CVE-2026-64677MEDIUM5.9Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not ...
CVE-2026-64665HIGH8.1Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was ...
CVE-2026-64664MEDIUM4.3Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Cont...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now