2026 CVE Vulnerabilities

50,938 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-39661HIGH7.5Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2026-25713HIGH7.8MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability
CVE-2026-25104HIGH7.8MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability
CVE-2026-8047HIGH8.7The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited ...
CVE-2026-8046HIGH8.1The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged ...
CVE-2026-44469HIGH7The affected product extracts installation files to a temporary directory with incorrect default permissions during admi...
CVE-2026-44468HIGH8.5The affected product creates a directory with insecure default permissions during administrative installation. This allo...
CVE-2026-9496HIGH7.7Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha...
CVE-2026-9495HIGH7.3Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the mid...
CVE-2026-9528HIGH7.3A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the fil...
CVE-2026-9526HIGH7.3A vulnerability was found in itsourcecode Electronic Judging System 1.0. This vulnerability affects unknown code of the ...
CVE-2026-9525HIGH7.3A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /...
CVE-2026-9523HIGH7.3A vulnerability was detected in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 3000WEBV...
CVE-2026-9538HIGH7.5Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar heade...
CVE-2026-9521HIGH7.3A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState ...
CVE-2026-42497HIGH7.5Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directo...
CVE-2026-9517HIGH7.3A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown fun...
CVE-2026-48837HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements...
CVE-2026-45438HIGH7.5Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured ...
CVE-2026-45216HIGH8.8Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects...
CVE-2026-45209HIGH7.5Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access...
CVE-2026-39436HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affe...
CVE-2026-24937HIGH7.2Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows ...
CVE-2026-48848HIGH7.2Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascadi...
CVE-2026-48844HIGH7.5Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues o...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now