2026 CVE Vulnerabilities

50,972 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-18682LOW3.1A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api...
CVE-2026-10849HIGH7.5The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update ser...
CVE-2026-69246HIGH7.2Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and...
CVE-2026-69245MEDIUM6.5Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of ...
CVE-2026-69244HIGH7.1AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap r...
CVE-2026-69243MEDIUM6.3AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were v...
CVE-2026-69240CRITICAL9.8Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracl...
CVE-2026-67976HIGH7.5The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allo...
CVE-2026-67972HIGH7.5An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data...
CVE-2026-66065HIGH8.4Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to ...
CVE-2026-52521HIGH8.1A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via th...
CVE-2026-52520MEDIUM5.4Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/...
CVE-2026-52102CRITICAL9.8An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to exe...
CVE-2026-51775CRITICAL9.8SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the applicati...
CVE-2026-51190CRITICAL9.8The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spaw...
CVE-2026-49132MEDIUM5.4OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to injec...
CVE-2026-49131MEDIUM5.4OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with fir...
CVE-2026-48113HIGH8.5Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated client...
CVE-2026-48063CRITICAL9.3Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baile...
CVE-2026-48061MEDIUM5.9Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypa...
CVE-2026-41447HIGH8.5FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbit...
CVE-2026-18738MEDIUM4.7Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote att...
CVE-2026-18737HIGH7.1Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL...
CVE-2026-18736MEDIUM5.3Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the serve...
CVE-2026-18733HIGH8.8A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now