2026 CVE Vulnerabilities

50,938 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-18895HIGH8.8A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /go...
CVE-2026-18859HIGH7.3A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/u...
CVE-2026-18856MEDIUM4.7A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFil...
CVE-2026-46334HIGH8.7OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a d...
CVE-2026-45809HIGH8.7OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a d...
CVE-2026-45705MEDIUM5.3OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the fin...
CVE-2026-18854HIGH7.3A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element ...
CVE-2026-18853MEDIUM5.3A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the fu...
CVE-2026-18852LOW3.3A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This imp...
CVE-2026-18103MEDIUM4.9A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Program...
CVE-2026-45537CRITICAL9.1OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the con...
CVE-2026-18819MEDIUM4.3A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vul...
CVE-2026-18818MEDIUM6.3A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView o...
CVE-2026-70620MEDIUM6.8Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attacke...
CVE-2026-70619HIGH8.8Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users ...
CVE-2026-70594MEDIUM6.7Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions ...
CVE-2026-70593MEDIUM6.6Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff...
CVE-2026-70592MEDIUM5.5Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overw...
CVE-2026-70591MEDIUM4.1Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin ima...
CVE-2026-70590MEDIUM4.8Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed password...
CVE-2026-70589MEDIUM4.8Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to rede...
CVE-2026-67862HIGH7.5open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c...
CVE-2026-67861HIGH7.5An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemo...
CVE-2026-67860HIGH7.5open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database ...
CVE-2026-67859HIGH7.5Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discover...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now