2026 CVE Vulnerabilities

50,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-59913HIGH7.8Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Criti...
CVE-2026-59912HIGH7.8Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnera...
CVE-2026-38447CRITICAL9.8osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with ...
CVE-2026-38446MEDIUM6.1A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread e...
CVE-2026-38444MEDIUM6.1osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is...
CVE-2026-18616CRITICAL9.8A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of...
CVE-2026-18615CRITICAL9.8A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate...
CVE-2026-18614CRITICAL9.8A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file ...
CVE-2026-61524HIGH8.6WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature th...
CVE-2026-61523HIGH8.6WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated...
CVE-2026-40717HIGH7.8Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnera...
CVE-2026-18613CRITICAL9.8A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of t...
CVE-2026-18612CRITICAL9.8A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/p...
CVE-2026-69153MEDIUM5.3PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract ...
CVE-2026-69152HIGH7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3...
CVE-2026-69151MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-69149MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-68945MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-68930MEDIUM6.5Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for reci...
CVE-2026-68869Rejected reason: This CVE ID was assigned in error. Upon further review, the reported issue does not represent a securit...
CVE-2026-67612MEDIUM4.8OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that al...
CVE-2026-67611HIGH8.6OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to ci...
CVE-2026-67610HIGH8.1OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoi...
CVE-2026-61372HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. Thi...
CVE-2026-41453HIGH8.8Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated use...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now