2026 CVE Vulnerabilities

48,018 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-40524HIGH8.1FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the fil...
CVE-2026-40523HIGH8.1FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Audit Trail report handler that allows authe...
CVE-2026-40522HIGH7.1FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows au...
CVE-2026-40521HIGH8.8FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authe...
CVE-2026-13676HIGH7.5fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The I...
CVE-2026-13568HIGH7.3A weakness has been identified in SourceCodester Inventory Management System 1.0. This vulnerability affects unknown cod...
CVE-2026-13566HIGH7.3A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u...
CVE-2026-13565HIGH7.3A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerabi...
CVE-2026-13165HIGH8.6SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but ex...
CVE-2026-12856HIGH8.8A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extensio...
CVE-2026-11979HIGH7.8libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. T...
CVE-2026-41992HIGH7.5GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shar...
CVE-2026-13564HIGH8.8A vulnerability was found in Edimax EW-7478APC 1.04. Affected is the function formPPPoESetup of the file /goform/formPPP...
CVE-2026-13563HIGH8.8A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/fo...
CVE-2026-13562HIGH8.8A flaw has been found in Edimax EW-7478APC 1.04. This affects the function formiNICSiteSurvey of the file /goform/formiN...
CVE-2026-13559HIGH7.3A weakness has been identified in code-projects Real State Services 1.0. Impacted is an unknown function of the file /si...
CVE-2026-57346HIGH7.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy al...
CVE-2026-25707HIGH8.8A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by re...
CVE-2026-13555HIGH7.3A vulnerability was found in itsourcecode Online Hotel Management System 1.0. Affected by this issue is some unknown fun...
CVE-2026-13553HIGH7.3A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /a...
CVE-2026-13552HIGH7.3A vulnerability was detected in itsourcecode Online Hotel Management System 1.0. This impacts an unknown function of the...
CVE-2026-22078HIGH7.3Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perfor...
CVE-2026-13551HIGH7.3A security vulnerability has been detected in itsourcecode Baptism Information Management System 1.0. This affects an un...
CVE-2026-13550HIGH7.3A weakness has been identified in itsourcecode Baptism Information Management System 1.0. The impacted element is an unk...
CVE-2026-13547HIGH7.3A vulnerability was determined in Hanwang e-Face General Management Platform 6.3.5.4. This issue affects some unknown pr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now