2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-6824HIGH8.4A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitiza...
CVE-2026-5768HIGH8.8The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing p...
CVE-2026-47179HIGH7.7Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.Ge...
CVE-2026-47125HIGH8.8Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/envi...
CVE-2026-45627HIGH8.2Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticat...
CVE-2026-44697HIGH8.6Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-...
CVE-2026-10108HIGH8.7xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_path:path} endpoint th...
CVE-2026-10107HIGH7.7MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated...
CVE-2026-10105HIGH8.7agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inj...
CVE-2026-45662HIGH8.8Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dok...
CVE-2026-39276HIGH7.2The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrator...
CVE-2026-35674HIGH8.8OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped client...
CVE-2026-35630HIGH8OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to ...
CVE-2026-32905HIGH8.7OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows no...
CVE-2026-10069HIGH8.7A vulnerability has been found in Shibby Tomato 1.28. The impacted element is an unknown function of the file usr/sbin/m...
CVE-2026-10068HIGH7.3A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of...
CVE-2026-10067HIGH8.8A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The mani...
CVE-2026-10066HIGH8.8A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the ...
CVE-2026-10065HIGH8.8A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file ...
CVE-2026-39292HIGH7.3Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder...
CVE-2026-46510HIGH8.2form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys ...
CVE-2026-45707HIGH8.1n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-45615HIGH8.2mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decod...
CVE-2026-45578HIGH8.8WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The...
CVE-2026-45555HIGH7.8Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now