2026 CVE Vulnerabilities

49,638 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-44698HIGH8.3Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for ...
CVE-2026-44239HIGH8.8FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes P...
CVE-2026-44238HIGH8.8FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through...
CVE-2026-44237HIGH8.1FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently ...
CVE-2026-40528HIGH7.8OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_valu...
CVE-2026-10073HIGH8.7DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to ...
CVE-2026-10072HIGH8.6DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to up...
CVE-2026-9509HIGH8.7An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated...
CVE-2026-48527HIGH8.7HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by...
CVE-2026-9809HIGH7.6A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project ...
CVE-2026-9808HIGH7.1An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain co...
CVE-2026-46579HIGH7.5A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP fronte...
CVE-2026-6075HIGH8.1The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl...
CVE-2026-49196HIGH7.2The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary she...
CVE-2026-49195HIGH8.8Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any...
CVE-2026-10056HIGH7.5CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default ...
CVE-2026-4776HIGH7.1An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitiz...
CVE-2026-9493HIGH7.1Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing...
CVE-2026-8070HIGH7.3Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s vali...
CVE-2026-7480HIGH7.3An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local u...
CVE-2026-9999HIGH8.8Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execu...
CVE-2026-9998HIGH8.3Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rend...
CVE-2026-9997HIGH8.3Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rende...
CVE-2026-9995HIGH8.8Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code ins...
CVE-2026-9994HIGH8.3Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now