2026 CVE Vulnerabilities

48,325 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-44691HIGH8.8In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/t...
CVE-2026-44688HIGH8.8In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its...
CVE-2026-8461HIGH8.8An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial...
CVE-2026-56012HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi...
CVE-2026-54224HIGH7.1UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile o...
CVE-2026-54223HIGH8.6UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any f...
CVE-2026-54222HIGH8.6UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to inte...
CVE-2026-54220HIGH8.6uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an ...
CVE-2026-50141HIGH7.1Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's ...
CVE-2026-42488HIGH8.1Some shadow paging errors paths will switch the page-tables without updating the currently running vCPU reference. This...
CVE-2026-42487HIGH7.9HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the de...
CVE-2026-40456HIGH8.6An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address p...
CVE-2026-40455HIGH8.6An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within the "tarifflist.php" m...
CVE-2026-11958HIGH7.3Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and pr...
CVE-2026-11719HIGH8.1An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement...
CVE-2026-8811HIGH7.1SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An atta...
CVE-2026-55746HIGH7.6Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage...
CVE-2026-55744HIGH8.6Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage ...
CVE-2026-55741HIGH8.8Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configu...
CVE-2026-11395HIGH7.2The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin...
CVE-2026-9860HIGH8.8The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all ver...
CVE-2026-12505HIGH7.8A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges befor...
CVE-2026-12407HIGH8.8The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to,...
CVE-2026-48764HIGH8.2TypeBot is a chatbot builder tool. In versions prior to 3.17.2, SSRF validation is implemented by resolving a hostname o...
CVE-2026-53676HIGH8.6ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now