2026 CVE Vulnerabilities

50,938 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-67858HIGH7.5Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast di...
CVE-2026-67857HIGH7.5open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/u...
CVE-2026-67856HIGH7.5An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscri...
CVE-2026-67855HIGH7.5open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMA...
CVE-2026-52370MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execu...
CVE-2026-51144MEDIUM6.1Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker ...
CVE-2026-45103HIGH7.5OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP...
CVE-2026-45100CRITICAL9.1OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta ...
CVE-2026-45084HIGH8.7OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of ...
CVE-2026-18817LOW2.2A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAut...
CVE-2026-18816MEDIUM5A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file...
CVE-2026-18814HIGH7.3A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. Th...
CVE-2026-70588MEDIUM5Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin fail...
CVE-2026-70554CRITICAL9.8MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary cod...
CVE-2026-70494HIGH8.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELE...
CVE-2026-70493MEDIUM6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built...
CVE-2026-70492HIGH8.7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/...
CVE-2026-70491MEDIUM6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /ap...
CVE-2026-70490MEDIUM6.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the termi...
CVE-2026-70489MEDIUM6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automatio...
CVE-2026-70488MEDIUM4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync ...
CVE-2026-70487MEDIUM5.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline di...
CVE-2026-67979CRITICAL9.1Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows at...
CVE-2026-66902CRITICAL9.8Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated sy...
CVE-2026-66901HIGH7.5Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now