2026 CVE Vulnerabilities

48,877 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-50733HIGH8.8Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), a...
CVE-2026-49493HIGH8.8Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the block...
CVE-2026-49492HIGH8.8Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not val...
CVE-2026-45749HIGH8.1Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST ...
CVE-2026-45745HIGH8Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting i...
CVE-2026-45743HIGH8.1Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. 16 file-ma...
CVE-2026-45327HIGH8.2TinyIce is a streaming server for audio and video. In versions 0.8.95 through 2.4.1, missing authentication on WebRTC in...
CVE-2026-45291HIGH7.5Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1....
CVE-2026-45290HIGH7.5Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1....
CVE-2026-36501HIGH7.5An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Serv...
CVE-2026-2379HIGH8.2On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibi...
CVE-2026-11344HIGH7.3A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file n...
CVE-2026-11342HIGH7.3A vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown functi...
CVE-2026-48111HIGH7.17-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an off-by-one out-of-bounds ...
CVE-2026-48103HIGH7.17-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain an off-by-one heap out-of-bo...
CVE-2026-11339HIGH8.8A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_41CF20 of the fil...
CVE-2026-48095HIGH8.87-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerab...
CVE-2026-48092HIGH8.17-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain a heap memory disclosure via...
CVE-2026-11334HIGH7.3A vulnerability was detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979...
CVE-2026-50234HIGH8.7Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrar...
CVE-2026-50232HIGH7.2Lyrion Music Server 9.2.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious...
CVE-2026-50231HIGH7.2Lyrion Music Server 9.2.0 contains an unauthenticated stored cross-site scripting vulnerability in the log viewer that a...
CVE-2026-11369HIGH7.1The Comment API (GET /api/Comment and POST /api/Comment) in the affected application fails to perform authorization chec...
CVE-2026-50264HIGH7.8An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A cli...
CVE-2026-50261HIGH7.8A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multipl...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now