2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-94491HIGH7.3A weakness has been identified in Yonyou KSOA 9.0. This affects an unknown part of the file /cardcase/search_list.jsp. E...
CVE-2026-93712HIGH7.5Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the ...
CVE-2026-93710HIGH7.5Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route that a dying hook refused when the exception handler ...
CVE-2026-94425HIGH8.8A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_1400...
CVE-2026-94627HIGH7.5vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child reque...
CVE-2026-94626HIGH7.5vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoi...
CVE-2026-94624HIGH7.5vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configur...
CVE-2026-94623HIGH7.5vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation tha...
CVE-2026-94622HIGH7.5vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for pre...
CVE-2026-94540HIGH7.7DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, r...
CVE-2026-94535HIGH7.1lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows auth...
CVE-2026-94534HIGH7.1lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allo...
CVE-2026-88738HIGH8.8Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload fu...
CVE-2026-79079HIGH7.8An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/...
CVE-2026-65980HIGH7.9Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c...
CVE-2026-61652HIGH8.7Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issu...
CVE-2026-59814HIGH7.6Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7...
CVE-2026-55210HIGH7.4Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2...
CVE-2026-94424HIGH8.8A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_14000...
CVE-2026-88746HIGH7.1idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_deal.php.
CVE-2026-88411HIGH7.5Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 lead...
CVE-2026-88410HIGH7.1The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected ...
CVE-2026-88409HIGH8.8FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix functio...
CVE-2026-88407HIGH7.5An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20...
CVE-2026-88406HIGH7.5FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses func...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now