2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-79316HIGH7.6An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configur...
CVE-2026-77523HIGH7.4MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the model parameter form route a...
CVE-2026-73553HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-61647HIGH7.1NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content ...
CVE-2026-55105HIGH7.7Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.1...
CVE-2026-49453HIGH7Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.1...
CVE-2026-49450HIGH7.1Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2...
CVE-2026-81469HIGH7.8Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A l...
CVE-2026-73552HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-73550HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-73548HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-73547HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-73546HIGH7.4Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-73513HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-73512HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,...
CVE-2026-58269HIGH8.1Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0,...
CVE-2026-55897HIGH8.8luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router in...
CVE-2026-55159HIGH8.8luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, ...
CVE-2026-52835HIGH7Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the import_config handle...
CVE-2026-49811HIGH8.4Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resourc...
CVE-2026-94501HIGH8.8jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authent...
CVE-2026-94497HIGH8.3jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resour...
CVE-2026-94496HIGH8.3jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to mo...
CVE-2026-94495HIGH7.1jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authen...
CVE-2026-94412HIGH8.8jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authen...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now