2026 CVE Vulnerabilities

49,206 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-35080HIGH8.1The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insuffic...
CVE-2026-35079HIGH8.1The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient...
CVE-2026-35078HIGH8.1The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficien...
CVE-2026-35077HIGH8.1The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insuffi...
CVE-2026-35076HIGH8.1The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insuffici...
CVE-2026-41032HIGH7.5It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some...
CVE-2026-4035HIGH7.7A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gatew...
CVE-2026-50031HIGH7.5ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Manag...
CVE-2026-10704HIGH7.3A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the func...
CVE-2026-9516HIGH7.5Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter...
CVE-2026-9334HIGH7.3Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref i...
CVE-2026-10694HIGH7.3A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function i...
CVE-2026-44654HIGH8.1LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a sha...
CVE-2026-42504HIGH7.5Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
CVE-2026-40108HIGH7.1GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XS...
CVE-2026-31942HIGH7.1LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an In...
CVE-2026-25861HIGH8.2QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attack...
CVE-2026-8936HIGH8.2Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested dire...
CVE-2026-49443HIGH8.8authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the...
CVE-2026-49144HIGH7.1BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js ...
CVE-2026-49143HIGH8.8BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows u...
CVE-2026-47201HIGH8.5authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Sou...
CVE-2026-10620HIGH7.3A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index....
CVE-2026-10619HIGH7.3A vulnerability was detected in sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93a385485051800. This ...
CVE-2026-8036HIGH7.8Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now