2026 CVE Vulnerabilities

43,347 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-50063HIGH7.8A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi...
CVE-2026-50062HIGH7.8A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi...
CVE-2026-50061HIGH7.8A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi...
CVE-2026-50060HIGH7.8A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi...
CVE-2026-50059HIGH7.8A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi...
CVE-2026-50058HIGH7.8A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi...
CVE-2026-18972CRITICAL9.6An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-M...
CVE-2026-72610MEDIUM4.3A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta...
CVE-2026-72609HIGH7.1An SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff wit...
CVE-2026-72608MEDIUM6.5A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta...
CVE-2026-72607HIGH7.1A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta...
CVE-2026-72606HIGH7.5A server-side request forgery vulnerability in Pinry through 2.1.13 allows unauthenticated remote attackers to make the ...
CVE-2026-72605HIGH7.5A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary ...
CVE-2026-72604MEDIUM6.5A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete ar...
CVE-2026-72603CRITICAL9.9An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbit...
CVE-2026-72602HIGH7.5A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attacke...
CVE-2026-72601HIGH7.5A broken access control vulnerability in CSZ CMS 1.3.2 allows unauthenticated remote attackers to read all form submissi...
CVE-2026-72600HIGH7.5A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download...
CVE-2026-72599CRITICAL9.8An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the ne...
CVE-2026-72598MEDIUM6.5A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the se...
CVE-2026-72597MEDIUM6.5A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with ...
CVE-2026-72596HIGH8.1A broken access control vulnerability in Ghost Foundation Ghost 5.x allows authenticated Author-role users to delete pos...
CVE-2026-72595HIGH8.1A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update tic...
CVE-2026-72563HIGH8.1A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite ...
CVE-2026-72562HIGH8.8An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now