2026 CVE Vulnerabilities

52,012 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-58154CRITICAL9.2Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers. This issue affe...
CVE-2026-58153HIGH8.3Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting H...
CVE-2026-58152MEDIUM6.9Apache Traffic Server mishandles integers while decoding HPACK/XPACK headers, corrupting memory. This issue affects Apa...
CVE-2026-58151HIGH8.7Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control. This ...
CVE-2026-13425HIGH7.2The Database for CF7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Array Form Field Values in al...
CVE-2026-11973MEDIUM4.9The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in a...
CVE-2026-58150CRITICAL10Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This ...
CVE-2026-57834CRITICAL10Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Ser...
CVE-2026-41920CRITICAL9.3Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 th...
CVE-2026-35226HIGH7.1An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same n...
CVE-2026-33930HIGH8.2Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handl...
CVE-2026-33267CRITICAL9.1Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 ...
CVE-2026-24033MEDIUM5.3Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server....
CVE-2026-22068MEDIUM5.3Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: fr...
CVE-2026-18197MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allow...
CVE-2026-18192HIGH7.1VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to e...
CVE-2026-18191CRITICAL9.8VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to...
CVE-2026-63242MEDIUM4.3A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to ...
CVE-2026-63241LOW3.1An insecure direct object reference vulnerability in Koollab LMS allowed an authenticated user to query the course compl...
CVE-2026-63240MEDIUM4.3An information disclosure vulnerability in Koollab LMS allowed an authenticated learner to obtain correct quiz answers f...
CVE-2026-63239MEDIUM5.4A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 bucke...
CVE-2026-63238MEDIUM6.5An authentication bypass vulnerability in Koollab LMS allowed an unauthenticated attacker to take over any account, incl...
CVE-2026-63237MEDIUM4.8A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled s...
CVE-2026-63236LOW3.7An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name,...
CVE-2026-63235LOW3.7An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the se...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now